github.com/SpectoLabs/hoverfly
Go5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/SpectoLabs/hoverflypage 1 of 1
- CVE-2024-45388HIGHCVSS 7.5EG 8.2✓ Fixed in 1.10.32024-09-02
Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new simulation views from the contents of a user-specified file. T…
- CVE-2025-54123CRITICALCVSS 9.8EG 9.82025-09-10
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injection vulnerability at `/api/v2/hoverfly/middleware` endpoint due to insufficient validatio…
- CVE-2025-54376HIGHCVSS 7.5EG 7.5✓ Fixed in 1.12.02025-09-10
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middleware that guards the REST admin API. Consequently, an una…
- CVE-2026-50013HIGHCVSS 7.5EG 7.5✓ Fixed in 1.12.82026-07-14
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode ### Summary: When Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). Wh…
- CVE-2026-50018MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.12.82026-07-14
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions ### Summary: Remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow …
Check whether github.com/SpectoLabs/hoverfly is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/SpectoLabs/hoverfly CVEs against the assets you own.
Start Free Scan →