Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions
Modified: 7/21/2026
package
pkg:go/github.com/SpectoLabs/hoverfly
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions
Modified: 7/21/2026
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`)
Modified: 9/6/2024
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled
Modified: 9/24/2025
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode
Modified: 7/21/2026
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation
Modified: 9/17/2025
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly
Modified: 3/3/2026
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly
Modified: 3/3/2026
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly
Modified: 3/3/2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions in github.com/SpectoLabs/hoverfly
Modified: 7/21/2026
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode in github.com/SpectoLabs/hoverfly
Modified: 7/21/2026