Executive brief
Hoverfly is an API simulation tool used for development and testing. A flaw in its 'Diff' mode allows an attacker to crash the service by sending multiple simultaneous requests. This results in a total service outage, disrupting testing workflows and requiring a manual restart of the application.
Technical details
A race condition exists in the `AddDiff()` function within `core/hoverfly_service.go`. When Hoverfly is configured in 'Diff' mode, it attempts to write to the shared `responsesDiff` map without proper synchronization (mutex locking). Because Go's `net/http` server handles requests concurrently in separate goroutines, simultaneous requests trigger Go's built-in runtime race detector. This results in an unrecoverable 'fatal error: concurrent map read and map write', which immediately terminates the process. The vulnerability is fixed in version 1.12.8.
Affected products
- SpectoLabs hoverfly <= 1.12.7
Timeline
- 2026-06-03: patched: Version 1.12.8 released
- 2026-07-14: disclosed: GitHub Advisory published
References
- https://api.github.com/users/Kr1shna4garwal
- https://github.com/Kr1shna4garwal
- https://api.github.com/users/Kr1shna4garwal/gists%7B/gist_id%7D
- https://api.github.com/users/Kr1shna4garwal/repos
- https://avatars.githubusercontent.com/u/85845881?v=4
- https://api.github.com/users/Kr1shna4garwal/events%7B/privacy%7D