hoverfly vulnerabilities
CVEs whose affected-version data names the hoverfly package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-50013High· 7.5Hoverfly is an open source API simulation tool
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy…
▾ TwilightSpectoLabs · hoverflyEPSS 0.27%via NVD
CVE-2026-50018Medium· 6.5PoCHoverfly is an open source API simulation tool
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP con…
▾ TwilightSpectoLabs · hoverflyEPSS 0.30%via NVD