Home/Product/facebook hermes
Product

facebook hermes

30 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-22798
>= 0.8.1 and < 0.9.1
hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9
5.9MEDIUM
CVE-2025-1293
< 0.5.0
Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing
8.2HIGH
CVE-2023-30470
all versions
A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit
9.8CRITICAL
CVE-2023-28081
all versions
A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after
9.8CRITICAL
CVE-2023-25933
all versions
A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious at
9.8CRITICAL
CVE-2023-24833
< 2023-02-02
A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been us
7.5HIGH
CVE-2023-24832
< 2023-01-31
A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used by an attac
7.5HIGH
CVE-2023-23557
< 2023-01-10
An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be use
9.8CRITICAL
CVE-2023-23556
< 2023-02-02
An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by
9.8CRITICAL
CVE-2022-40138
< 2022-09-27
An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have be
9.8CRITICAL
CVE-2022-35289
< 0.12.0
A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 all
9.8CRITICAL
CVE-2022-32234
< 0.12.0
An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 allows att
9.8CRITICAL
CVE-2022-27810
< 0.12.0
It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed J
7.5HIGH
CVE-2021-24044
< 0.10.0
By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Her
9.8CRITICAL
CVE-2021-24045
< 0.10.0
A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0.
9.8CRITICAL
CVE-2021-24037
< 0.8.0
A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows
9.8CRITICAL
CVE-2021-23910
all versions
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. There is an out-of-b
5.3MEDIUM
CVE-2021-23909
all versions
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MCU allows r
6.3MEDIUM
CVE-2020-1896
< 0.5.0
A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https:
9.8CRITICAL
CVE-2019-19563
all versions
A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to device har
2.4LOW
CVE-2019-19562
all versions
An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hard
4.6MEDIUM
CVE-2019-19561
all versions
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device har
2.4LOW
CVE-2019-19560
all versions
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hard
4.6MEDIUM
CVE-2019-19557
all versions
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardw
2.4LOW
CVE-2019-19556
all versions
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to device hardwa
4.6MEDIUM
CVE-2020-1915
< 2020-09-25
An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 al
7.5HIGH
CVE-2020-1914
< 2020-10-01
A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c9661
9.8CRITICAL
CVE-2020-1913
<= 0.4.3
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71
8.1HIGH
CVE-2020-1912
<= 0.4.3
An out-of-bounds read/write vulnerability when executing lazily compiled inner generator functions in Facebook Hermes prior to com
8.1HIGH
CVE-2020-1911
< 0.4.3
A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook
9.8CRITICAL
threatengine.sh