Hoverfly is a service virtualization and API mocking tool whose disclosed vulnerabilities center on its core product and recur through weakness classes including sensitive information exposure, improper authentication, input validation gaps, path traversal, and OS command injection. These patterns reflect the exposure inherent in a tool that intercepts and simulates network traffic and processes user-supplied configurations; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hoverfly over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-45388HIGH Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new sim | Sep 2, 2024 | 7.5 | 63 | NO | YES |
CVE-2025-54123CRITICAL Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injection vulnerability at `/api/v2/ | Sep 10, 2025 | 9.8 | 50 | NO | YES |
CVE-2025-54376HIGH Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middle | Sep 10, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hoverfly.
Media articles that mention a CVE ID that affects a product developed by Hoverfly — matched by CVE ID, not by vendor name.