—
GO-2025-3944
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly
Details
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation in github.com/SpectoLabs/hoverfly
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/SpectoLabs/hoverfly
Introduced in:
0No fixed version published yet for github.com/SpectoLabs/hoverfly (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-r4h8-hfp2-ggmf[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-54123[ADVISORY]
- https://github.com/SpectoLabs/hoverfly/commit/17e60a9bc78826deb4b782dca1c1abd3dbe60d40[FIX]
- https://github.com/SpectoLabs/hoverfly/commit/a9d4da7bd7269651f54542ab790d0c613d568d3e[FIX]
- https://github.com/SpectoLabs/hoverfly/pull/1203[FIX]
- https://github.com/SpectoLabs/hoverfly/blob/master/core/hoverfly_service.go#L173[WEB]
- https://github.com/SpectoLabs/hoverfly/blob/master/core/middleware/local_middleware.go#L13[WEB]
- https://github.com/SpectoLabs/hoverfly/blob/master/core/middleware/middleware.go#L93[WEB]