Github.com/spectolabs/hoverfly
This hub aggregates every CVE we track for Github.com/spectolabs/hoverfly, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2CRITICAL1
Monthly trend
1
0
0
0
0
0
0
0
0
0
0
0
2
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 3 most recently published vulnerabilities affecting Github.com/spectolabs/hoverfly.
- CVE-2025-54376Hoverfly's WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled.7.5
- CVE-2025-54123Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation9.8
- CVE-2024-45388Arbitrary file read in the `/api/v2/simulation` endpoint in hoverfly (`GHSL-2023-274`)7.5
Product normalization is registry-driven with AI assist and human review. How it works