CVE-2026-50013: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in SpectoLabs hoverfly
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the normal case for any proxy), the concurrent map writes trigger Go's built-in race detector which causes a `fatal error: concurrent map read and map write`, immediately killing the entire Hoverfly process. This is trivially exploitable by sending multiple simultaneous requests. Version 1.12.8 patches the issue.
AI Analysis
Technical Summary
Hoverfly versions prior to 1.12.8 contain a race condition (CWE-362) in the AddDiff() function when running in Diff mode. The function writes to the shared responsesDiff map without any mutex or synchronization. Under concurrent proxy requests, this causes Go's runtime to detect concurrent map read and write operations, triggering a fatal error that crashes the Hoverfly process. This vulnerability is trivially exploitable by sending multiple simultaneous requests. Version 1.12.8 includes a patch that addresses this improper synchronization.
Potential Impact
Exploitation of this vulnerability causes the Hoverfly process to crash immediately due to concurrent map access errors. This results in a denial of service (DoS) condition, disrupting API simulation and proxy functionality. There is no impact on confidentiality or integrity, but availability is severely affected.
Mitigation Recommendations
Upgrade Hoverfly to version 1.12.8 or later, where this race condition has been fixed. No other mitigations are indicated or required.
CVE-2026-50013: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in SpectoLabs hoverfly
Description
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the normal case for any proxy), the concurrent map writes trigger Go's built-in race detector which causes a `fatal error: concurrent map read and map write`, immediately killing the entire Hoverfly process. This is trivially exploitable by sending multiple simultaneous requests. Version 1.12.8 patches the issue.
CVSS v3.1
Score 7.5high
Affected software
SpectoLabs
hoverfly
pkg:golang/github.com/spectolabs/hoverflyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Hoverfly versions prior to 1.12.8 contain a race condition (CWE-362) in the AddDiff() function when running in Diff mode. The function writes to the shared responsesDiff map without any mutex or synchronization. Under concurrent proxy requests, this causes Go's runtime to detect concurrent map read and write operations, triggering a fatal error that crashes the Hoverfly process. This vulnerability is trivially exploitable by sending multiple simultaneous requests. Version 1.12.8 includes a patch that addresses this improper synchronization.
Potential Impact
Exploitation of this vulnerability causes the Hoverfly process to crash immediately due to concurrent map access errors. This results in a denial of service (DoS) condition, disrupting API simulation and proxy functionality. There is no impact on confidentiality or integrity, but availability is severely affected.
Mitigation Recommendations
Upgrade Hoverfly to version 1.12.8 or later, where this race condition has been fixed. No other mitigations are indicated or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-02T22:46:02.579Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa4737691cc7f3848ae20c2
Added to database: 09/11/2026, 21:32:38 UTC
Last enriched: 09/11/2026, 21:47:10 UTC
Last updated: 09/11/2026, 22:24:50 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.