Description
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each triggered proxy request spawns a goroutine that blocks indefinitely on `http.DefaultClient.Do()`. An attacker can cause unbounded goroutine accumulation leading to memory exhaustion and process crash (OOM kill). Unlike local post-serve action execution, this requires no binary execution, only a URL pointing to a non-responsive endpoint. Version 1.12.8 patches the issue.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post‑serve actions use http.DefaultClient without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts a TCP connection but never responds), each triggered proxy request spawns a goroutine that blocks indefinitely on http.DefaultClient.Do(). An attacker can cause unbounded goroutine accumulation leading to memory exhaustion and a process crash (OOM kill). This denial of service does not require binary execution; it only needs a URL pointing to a non‑responsive endpoint. Version 1.12.8 adds a timeout to remote post‑serve calls, mitigating the resource‑exhaustion weakness (CWE‑400, CWE‑770).

Affected Systems

SpectoLabs Hoverfly versions earlier than 1.12.8 are affected. The vulnerability is present regardless of whether the remote endpoint is on the local network or external, and does not depend on privileged access.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is < 1%, suggesting that exploitation is currently unlikely. Hoverfly is not listed in CISA KEV. An attacker can trigger the vulnerability by supplying a URL for a non‑responsive endpoint in the post‑serve configuration; no authentication or privileged operations are required. Each trigger creates a goroutine that never terminates, leading to a gradual buildup of goroutines and eventual crash of the Hoverfly process.

Generated by OpenCVE AI on September 15, 2026 at 19:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hoverfly to version 1.12.8 or later, which adds a timeout to remote post‑serve action calls.
  • If an upgrade cannot be performed immediately, point post‑serve actions to a responsive endpoint to prevent goroutine leaks.
  • Monitor system metrics, including goroutine count, to detect potential resource exhaustion.

Generated by OpenCVE AI on September 15, 2026 at 19:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-42j2-w334-qxw7 Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions
History

Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Spectolabs
Spectolabs hoverfly
Vendors & Products Spectolabs
Spectolabs hoverfly

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each triggered proxy request spawns a goroutine that blocks indefinitely on `http.DefaultClient.Do()`. An attacker can cause unbounded goroutine accumulation leading to memory exhaustion and process crash (OOM kill). Unlike local post-serve action execution, this requires no binary execution, only a URL pointing to a non-responsive endpoint. Version 1.12.8 patches the issue.
Title Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions
Weaknesses CWE-400
CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Spectolabs Hoverfly
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:28:30.918Z

Reserved: 2026-06-02T22:46:02.579Z

Link: CVE-2026-50018

cve-icon Vulnrichment

Updated: 2026-09-14T19:28:04.891Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T22:16:37.950

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-50018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:45:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling