THREAT OPS › Threat News › [NVD] CVE-2026-50018 (MEDIUM 6.5) — Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each triggered
[NVD] CVE-2026-50018 (MEDIUM 6.5) — Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each triggered
CVE-2026-50018 CVSS: 6.5 MEDIUM Published: 2026-09-11T22:16:37.950
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each triggered proxy request spawns a goroutine that blocks indefi
Indicators of compromise
- CVE-2026-50018cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-50018