Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

hermes — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in hermes, with AI-generated Chinese analysis, references, and POCs.

This page provides a vulnerability aggregation dashboard for Hermes, an open-source enterprise service bus developed by Camunda. It collects and organizes known security issues related to this specific product ecosystem, focusing on common weakness types such as cross-site scripting, improper access control, and configuration errors. The content covers vulnerabilities reported from its initial releases through recent updates, ensuring a comprehensive historical perspective on the product's security posture. Here, users can track a vendor's advisories to stay informed about remediation efforts and patch availability. Additionally, analysts can understand a specific weakness class within the context of service bus architectures, observing how different flaws manifest across similar components. The page also allows stakeholders to look up a product's vulnerability history, facilitating risk assessments and compliance audits by providing a clear timeline of disclosed issues. By centralizing this data, the resource supports developers, security teams, and administrators in making informed decisions about deployment, upgrading, and mitigation strategies. The aggregation process filters out noise to present relevant, actionable intelligence, helping organizations prioritize their security operations effectively. This structured approach enables a deeper understanding of the threat landscape specific to Hermes, highlighting trends and recurring patterns that might otherwise remain obscured in fragmented reports. Ultimately, it serves as a single source of truth for evaluating the ongoing security health of the Hermes platform.

Vendor: Facebook

CVE IDTitleCVSSSeverityPublished
CVE-2026-22798 hermes's raw options logging may disclose secrets passed in via subcommand options argument CWE-532 5.9 Medium2026-01-12
CVE-2023-30470 Facebook Hermes 资源管理错误漏洞 9.8 -2023-05-18
CVE-2023-28081 Facebook Hermes 资源管理错误漏洞 8.1 -2023-05-18
CVE-2023-25933 Facebook Hermes 安全漏洞 9.8 -2023-05-18
CVE-2023-24833 Facebook Hermes 资源管理错误漏洞 7.5 -2023-05-18
CVE-2023-24832 Facebook Hermes 代码问题漏洞 7.5 -2023-05-18
CVE-2023-23557 Facebook Hermes 安全漏洞 10.0 -2023-05-18
CVE-2023-23556 Facebook Hermes 缓冲区错误漏洞 9.8 -2023-05-18
CVE-2022-32234 Facebook Hermes 缓冲区错误漏洞 CWE-787 9.8 -2022-10-11
CVE-2022-40138 Facebook Hermes 安全漏洞 CWE-681 9.8 -2022-10-11
CVE-2022-35289 Facebook Hermes 输入验证错误漏洞 CWE-680 9.8 -2022-10-11
CVE-2022-27810 Facebook Hermes 安全漏洞 CWE-674 7.5 -2022-10-06
CVE-2021-24044 Facebook Hermes 安全漏洞 CWE-843 9.8 -2022-01-15
CVE-2021-24045 Facebook Hermes 安全漏洞 CWE-843 9.1 -2021-12-13
CVE-2021-24037 Facebook Hermes 资源管理错误漏洞 CWE-416 8.1 -2021-06-15
CVE-2020-1896 Facebook Hermes 缓冲区错误漏洞 CWE-121 9.8 -2021-02-02
CVE-2020-1915 Facebook Hermes 缓冲区错误漏洞 CWE-125 5.9 -2020-10-26
CVE-2020-1914 Facebook Hermes 安全漏洞 CWE-670 9.8 -2020-10-08
CVE-2020-1913 Facebook Hermes 安全漏洞 CWE-195 8.1 -2020-09-09
CVE-2020-1912 Facebook Hermes 缓冲区错误漏洞 CWE-787 8.1 -2020-09-09
CVE-2020-1911 Facebook Hermes 安全漏洞 CWE-843 8.1 -2020-09-04

All 21 known CVE vulnerabilities affecting hermes with full Chinese analysis, references, and POCs where available.