The Faraday Project maintains a focused penetration-testing and vulnerability-management platform whose security exposure centers on its core Faraday application and server-side request forgery weaknesses that can arise in web-facing collaborative tools. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Faraday Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54297HIGH Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the defau | Jun 24, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-33637MEDIUM Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override w | May 19, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-25765MEDIUM Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/conne | Feb 9, 2026 | 5.8 | 23 | NO | NO |
CVE-2021-27338MEDIUM Faraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter. | Jul 20, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Faraday Project.
Media articles that mention a CVE ID that affects a product developed by Faraday Project — matched by CVE ID, not by vendor name.