Skip to content

Conversation

@tommysitu
Copy link
Member

@tommysitu tommysitu commented Sep 9, 2025

For mitigating CVE-2025-54123:

  • The set middleware API should be disabled by default
  • You can still pass middleware when you start hoverfly
  • To enable the set middleware API for hot reloading of the middleware, you need to start hoverfly with the -enable-middleware-api flag
  • Add security implications and advice on using the middleware API in hoverfly documentation.

@tommysitu tommysitu merged commit 25f4e72 into master Sep 10, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants