Executive brief
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly
Affected products
- Go github.com/SpectoLabs/hoverfly
Junglewise Threat Intelligence
CVE-2025-54376 · Severity: medium · CVSS 4 · Published 2025-09-17
Technologies: github.com/SpectoLabs/hoverfly (Go). Vendors: Go.
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled in github.com/SpectoLabs/hoverfly