Skip to content
Noroxi

hoverfly records

3 published records for vendor hoverfly.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 24
  2. 25

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

3 records
  • Arbitrary file read in the `/api/v2/simulation` endpoint in hoverfly (`GHSL-2023-274`)

    HighCVSS 7.5Proof of conceptEPSS 56%

    hoverfly · hoverflySep 2, 2024

  • Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation

    CriticalCVSS 9.8Proof of conceptEPSS 11%

    hoverfly · hoverflySep 10, 2025

  • Hoverfly's WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled.

    HighCVSS 7.8No exploitEPSS 1%

    hoverfly · hoverflySep 10, 2025