Faraday develops vulnerability management and security assessment tools, with a narrow product footprint centered on its Edge and Faraday platforms. The observed exposure involves web-presentation input-handling issues, specifically cross-site scripting weaknesses that recur in web-facing interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Faraday over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54297HIGH Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the defau | Jun 24, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-33637MEDIUM Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override w | May 19, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-25765MEDIUM Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/conne | Feb 9, 2026 | 5.8 | 23 | NO | NO |
CVE-2021-27338MEDIUM Faraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter. | Jul 20, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Faraday.
Media articles that mention a CVE ID that affects a product developed by Faraday — matched by CVE ID, not by vendor name.