Junglewise Threat Intelligence

CVE-2025-54376: GO-2025-3945 - WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly

CVE-2025-54376 · Severity: medium · CVSS 4 · Published 2025-09-17

Technologies: github.com/SpectoLabs/hoverfly (Go). Vendors: Go.

Executive brief

WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly

Affected products

  • Go github.com/SpectoLabs/hoverfly

Related threats