Information Disclosure in Hoverfly API Simulation Tool by SpectoLabs
CVE-2025-54376

7.8HIGH

Key Information:

Vendor

Spectolabs

Status
Vendor
CVE Published:
10 September 2025

What is CVE-2025-54376?

Hoverfly, an open-source API simulation tool, suffers from an information disclosure vulnerability due to improper access control on its admin WebSocket endpoint. In affected versions (1.11.3 and earlier), this endpoint lacks the requisite authentication middleware that secures the REST admin API. As a result, unauthenticated attackers can exploit this vulnerability to stream sensitive application logs in real-time, revealing internal file paths and request/response bodies. This exposes potentially critical information that could be leveraged for further attacks. Users are encouraged to upgrade to version 1.12.0 or later to mitigate this risk.

Affected Version(s)

hoverfly < 1.12.0

References

CVSS V4

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.