Impact
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff writes to the shared responsesDiff map without any synchronization (no mutex). When multiple proxy requests are processed concurrently—the normal case for any proxy—concurrent map writes trigger Go's built-in race detector read and map write, and immediately killing the entire Hoverfly process. This flaw is trivially exploitable by sending multiple simultaneous requests, leading to a predictable crash. The issue was patched in version 1.12.8. This reflects a CWE‑362 and CWE‑820 weakness.
Affected Systems
SpectoLabs Hoverfly prior to v1.12.8, when running in Diff mode and processing concurrent traffic. Version 1.12.8 onward contains the fix.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact and requires prompt mitigation. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV does not require special privileges: an mode via network traffic to the Hoverfly proxy, and the vulnerability is trivially exploitable by standard HTTP request tools. This corresponds to CWE‑362 and CWE‑820 weaknesses.
OpenCVE Enrichment
Github GHSA