By vendor

Faraday_project vulnerabilities

Known CVEs affecting Faraday_project products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-54297HIGH 7.5

    Faraday, a popular Ruby HTTP client library, contains a denial-of-service vulnerability in its default query parameter parser. When an application accepts and processes user-supplied query strings through Faraday, an attacker can craft a deeply nested parameter structure that exhausts the Ruby interpreter's call stack, crashing the thread or worker handling that request. This affects Faraday versions 1.0.0 through 1.10.5 and 2.x through 2.14.2. The vulnerability has been patched in versions 1.10.6 and 2.14.3.