Impact
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post‑serve actions use http.DefaultClient without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts a TCP connection but never responds), each triggered proxy request spawns a goroutine that blocks indefinitely on http.DefaultClient.Do(). An attacker can cause unbounded goroutine accumulation leading to memory exhaustion and a process crash (OOM kill). This denial of service does not require binary execution; it only needs a URL pointing to a non‑responsive endpoint. Version 1.12.8 adds a timeout to remote post‑serve calls, mitigating the resource‑exhaustion weakness (CWE‑400, CWE‑770).
Affected Systems
SpectoLabs Hoverfly versions earlier than 1.12.8 are affected. The vulnerability is present regardless of whether the remote endpoint is on the local network or external, and does not depend on privileged access.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is < 1%, suggesting that exploitation is currently unlikely. Hoverfly is not listed in CISA KEV. An attacker can trigger the vulnerability by supplying a URL for a non‑responsive endpoint in the post‑serve configuration; no authentication or privileged operations are required. Each trigger creates a goroutine that never terminates, leading to a gradual buildup of goroutines and eventual crash of the Hoverfly process.
OpenCVE Enrichment
Github GHSA