CVE-2025-54376: Hoverfly
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middleware that guards the REST admin API. Consequently, an unauthenticated remote attacker can stream real-time application logs (information disclosure) and/or gain insight into internal file paths, request/response bodies, and other potentially sensitive data emitted in logs. Version 1.12.0 contains a fix for the issue.
Affected products
- Hoverfly Hoverfly: before 1.12.0 (fixed in 1.12.0)
Published 2025-09-10. Last modified 2026-06-17.