以下是该漏洞描述的中文翻译: Hoverfly 是一款开源的 API 模拟工具。在 1.12.8 版本之前,远程 post-serve 动作使用 且未配置任何超时机制。当远程端点不可达或故意响应缓慢(接受 TCP 连接但始终不返回响应)时,每个触发的代理请求都会生成一个在 上无限期阻塞的 goroutine。攻击者可以借此导致 goroutine 无限累积,最终引发内存耗尽和进程崩溃(OOM kill)。与本地 post-serve 动作的执行不同,该漏洞不需要执行二进制文件,只需提供一个指向无响应端点的 URL
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SpectoLabs | hoverfly | < 1.12.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet