CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-50018

mediumCVSS 6.5covered by 1 sourcefirst seen 2026-07-14
Summary: Remote post-serve actions use http.DefaultClient without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each triggered proxy request spawns a goroutine that blocks indefinitely on http.DefaultClient.Do(). An attacker can cause unbounded goroutine accumulation leading to memory exhaustion and process crash (OOM kill). Unlike local post-serve action execution, this requires no binary execution, only a URL pointing to a non-responsive endpoint. Details: 1. Remote actions executed in goroutines without timeout (core/hoverfly.go:224-228): go postServeAction.Execute(result.Pair, journalIDChannel, hf.Journal) Post-serve actions are executed in separate goroutines with no recovery wrapper. 2. HTTP client has no timeout (core/action/action.go:128-143): req, err := http.NewRequest("POST", action.Remote, bytes.NewBuffer(pairViewBytes)) // ... resp, err := http.DefaultClient.Do(req) // No timeout! Blocks forever. http.DefaultClient has zero timeout by default in Go. If the remote server: - Accepts the TCP connection but never sends a response - Establishes TLS but never completes the handshake - Uses TCP window size 0 (flow control stall) ...the goroutine blocks indefinitely. There is no context cancellation, no deadline, and no cleanup. 3. No goroutine limit or backpressure: There is no limit on how many post-serve action goroutines can be active simultaneously. Each matching proxy request spawns a new one unconditionally. 4. The goroutine is never cleaned up: The only exit path from Execute() is a successful (or failed) HTTP response. A non-responding server means the goroutine lives until the process is killed. Environment: - Hoverfly version: v1.12.7 - Operating System: macOS Darwin 25.4.0 - Go version: 1.26.2 - Configuration: Default (no flags required) POC: Step 1: Start a black-hole TCP listener (accepts connections, never responds) Option A: Use ncat ncat -l

⚡ Watch CVE-2026-50018

Get an email if CVE-2026-50018 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-50018

CVE.org record

Embed the live status

CVE-2026-50018 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-50018 status](https://www.csirts.com/badge/CVE-2026-50018)](https://www.csirts.com/cve/CVE-2026-50018)