CVE-2026-50013

HIGH CVSS 3.1: 7.5 EPSS 0.47%
Updated Sep 30, 2026
Hoverfly
Parameter Value
CVSS 7.5 (HIGH)
Type CWE-820, CWE-362 (Race Condition)
Vendor Hoverfly
Public PoC No

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the normal case for any proxy), the concurrent map writes trigger Go's built-in race detector which causes a `fatal error: concurrent map read and map write`, immediately killing the entire Hoverfly process.

This is trivially exploitable by sending multiple simultaneous requests. Version 1.12.8 patches the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Related Vulnerabilities