Description
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the normal case for any proxy), the concurrent map writes trigger Go's built-in race detector which causes a `fatal error: concurrent map read and map write`, immediately killing the entire Hoverfly process. This is trivially exploitable by sending multiple simultaneous requests. Version 1.12.8 patches the issue.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Process Crash)
Action: Apply Patch
AI Analysis

Impact

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff writes to the shared responsesDiff map without any synchronization (no mutex). When multiple proxy requests are processed concurrently—the normal case for any proxy—concurrent map writes trigger Go's built-in race detector read and map write, and immediately killing the entire Hoverfly process. This flaw is trivially exploitable by sending multiple simultaneous requests, leading to a predictable crash. The issue was patched in version 1.12.8. This reflects a CWE‑362 and CWE‑820 weakness.

Affected Systems

SpectoLabs Hoverfly prior to v1.12.8, when running in Diff mode and processing concurrent traffic. Version 1.12.8 onward contains the fix.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact and requires prompt mitigation. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV does not require special privileges: an mode via network traffic to the Hoverfly proxy, and the vulnerability is trivially exploitable by standard HTTP request tools. This corresponds to CWE‑362 and CWE‑820 weaknesses.

Generated by OpenCVE AI on September 15, 2026 at 20:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hoverfly to version 1.12.8 or later. The patch corrects the concurrent map write flaw (CWE‑362) and improper locking (CWE‑820).
  • If an immediate upgrade is not possible, disable Diff mode to eliminate exposure to the race condition caused by CWE‑362/CWE‑820 until the patch can be applied.
  • Implement automated monitoring and process restarts, such as using a container orchestration restart policy or a process supervisor, to reduce downtime if the process crashes.

Generated by OpenCVE AI on September 15, 2026 at 20:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qrh4-p6v4-mrfg Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Spectolabs
Spectolabs hoverfly
Vendors & Products Spectolabs
Spectolabs hoverfly

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the normal case for any proxy), the concurrent map writes trigger Go's built-in race detector which causes a `fatal error: concurrent map read and map write`, immediately killing the entire Hoverfly process. This is trivially exploitable by sending multiple simultaneous requests. Version 1.12.8 patches the issue.
Title Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode
Weaknesses CWE-362
CWE-820
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Spectolabs Hoverfly
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:17:21.942Z

Reserved: 2026-06-02T22:46:02.579Z

Link: CVE-2026-50013

cve-icon Vulnrichment

Updated: 2026-09-14T17:06:21.115Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T22:16:37.813

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-50013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:45:20Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-820

    Missing Synchronization