github.com/spectolabs/hoverfly
Lightweight service virtualization/ API simulation / API mocking tool for developers and testers
Activity
- Latest release
- 19h ago
- Total releases
- 65
- Cadence
- ~41 days
- Last 12 months
- 14
Reach
- Stars
- 2.5k
Details
- First release
- Dec 29, 2015
| Version | Released | |
|---|---|---|
v1.12.14
patch
1 CVE
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.14
patch
Dependencies (41)
+ 33 more |
|
v1.12.13
patch
1 CVE
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.13
patch
Dependencies (41)
+ 33 more |
|
v1.12.12
patch
1 CVE
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.12
patch
Dependencies (41)
+ 33 more |
|
v1.12.11
patch
1 CVE
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.11
patch
Dependencies (41)
+ 33 more |
|
v1.12.10
patch
1 CVE
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.10
patch
Dependencies (41)
+ 33 more |
|
v1.12.9
patch
1 CVE
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.9
patch
Dependencies (41)
+ 33 more |
|
v1.12.8
patch
1 CVE
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.8
patch
Dependencies (41)
+ 33 more |
|
v1.12.7
patch
3 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.7
patch
Dependencies (41)
+ 33 more |
|
v1.12.6
patch
3 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.6
patch
Dependencies (41)
+ 33 more |
|
v1.12.5
patch
3 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.5
patch
Dependencies (41)
+ 33 more |
|
v1.12.4
patch
3 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.4
patch
Dependencies (40)
+ 32 more |
|
v1.12.3
patch
3 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.3
patch
Dependencies (40)
+ 32 more |
|
v1.12.2
minor
3 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.2
minor
Dependencies (40)
+ 32 more |
|
v1.12.1
patch
3 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.1
patch
Dependencies (40)
+ 32 more |
|
v1.12.0
minor
3 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.12.0
minor
Dependencies (40)
+ 32 more |
|
v1.11.3
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.3
patch
Dependencies (40)
+ 32 more |
|
v1.11.2
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.2
patch
Dependencies (40)
+ 32 more |
|
v1.11.1
minor
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.1
minor
Dependencies (40)
+ 32 more |
|
v1.11.0
minor
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.0
minor
Dependencies (40)
+ 32 more |
|
v1.10.13
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.13
patch
Dependencies (40)
+ 32 more |
|
v1.10.12
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.12
patch
Dependencies (40)
+ 32 more |
|
v1.10.11
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.11
patch
Dependencies (40)
+ 32 more |
|
v1.10.10
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.10
patch
Dependencies (40)
+ 32 more |
|
v1.10.9
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.9
patch
Dependencies (40)
+ 32 more |
|
v1.10.6
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.6
patch
Dependencies (39)
+ 31 more |
|
v1.10.5
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.5
patch
Dependencies (39)
+ 31 more |
|
v1.10.4
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.4
patch
Dependencies (39)
+ 31 more |
|
v1.10.3
patch
4 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.3
patch
Dependencies (39)
+ 31 more |
|
v1.10.1
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.1
minor
Dependencies (39)
+ 31 more |
|
v1.9.5
patch
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.9.5
patch
Dependencies (39)
+ 31 more |
|
v1.9.2
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.9.2
minor
Dependencies (39)
+ 31 more |
|
v1.6.2
patch
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.6.2
patch
Dependencies (38)
+ 30 more |
|
v1.6.1
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.6.1
minor
Dependencies (38)
+ 30 more |
|
v1.5.3
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.3
minor
Dependencies (38)
+ 30 more |
|
v1.4.0
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (38)
+ 30 more |
|
v1.3.7
patch
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.7
patch
Dependencies (36)
+ 28 more |
|
v1.3.5
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.5
minor
Dependencies (36)
+ 28 more |
|
v1.2.0
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (35)
+ 27 more |
|
v1.1.5
patch
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.5
patch
|
|
v1.1.4
patch
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.4
patch
|
|
v1.1.0
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
minor
|
|
v1.0.1
major
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.1
major
|
|
v1.0.0-rc.1
pre
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0-rc.1
pre
|
|
v0.17.7
patch
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.17.7
patch
|
|
v0.17.6
patch
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.17.6
patch
|
|
v0.17.2
patch
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.17.2
patch
|
|
v0.17.0
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.17.0
minor
|
|
v0.16.0
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.16.0
minor
|
|
v0.15.1
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.15.1
minor
|
|
v0.13.0
minor
5 CVEs
CVE-2026-50013
GO-2026-5977
GHSA-qrh4-p6v4-mrfg
Jul 17, 2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-50018
GO-2026-5975
GHSA-42j2-w334-qxw7
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly Fixed in
1.12.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-54123
GO-2025-3944
GHSA-r4h8-hfp2-ggmf
Sep 17, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54376
GO-2025-3945
GHSA-jxmr-2h4q-rhxp
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly WebSocket endpoint Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-45388
GO-2024-3108
GHSA-6xx4-x46f-f897
Sep 06, 2024
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly Hoverfly allows an arbitrary file read in the Fixed in
1.10.3
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.0
minor
|