Junglewise Threat Intelligence

CVE-2026-50013: Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function wri

CVE-2026-50013 · Severity: high · CVSS 7.5 · Published 2026-09-11

Technologies: github.com/SpectoLabs/hoverfly (Go). Vendors: Go.

Executive brief

Hoverfly is an API simulation tool used for development and testing. A flaw in its 'Diff' mode allows an attacker to crash the service by sending multiple simultaneous requests. This results in a total service outage, disrupting testing workflows and requiring a manual restart of the application.

Technical details

A race condition exists in the `AddDiff()` function within `core/hoverfly_service.go`. When Hoverfly is configured in 'Diff' mode, it attempts to write to the shared `responsesDiff` map without proper synchronization (mutex locking). Because Go's `net/http` server handles requests concurrently in separate goroutines, simultaneous requests trigger Go's built-in runtime race detector. This results in an unrecoverable 'fatal error: concurrent map read and map write', which immediately terminates the process. The vulnerability is fixed in version 1.12.8.

Affected products

  • SpectoLabs hoverfly <= 1.12.7

Timeline

  • 2026-06-03: patched: Version 1.12.8 released
  • 2026-07-14: disclosed: GitHub Advisory published

References

Related threats