faraday
HTTP/REST API client library.
Activity
- Latest release
- 2mo ago
- Total releases
- 160
- Cadence
- ~17 days
- Last 12 months
- 5
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Dec 19, 2009
| Version | Released | |
|---|---|---|
1.10.6
patch
|
1.10.6
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.14.3
patch
| ||
2.14.2
patch
1 CVE
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.5
patch
1 CVE
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.10.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.14.1
patch
2 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.14.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.13.4
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.13.3
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.13.2
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.13.1
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.13.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.12.3
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.12.2
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.12.1
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.4
patch
2 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.10.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.12.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.11.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.10.1
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.10.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.9.2
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.9.1
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.9.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.8.1
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.8.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.12
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.11
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.10
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.9
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.8
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.7
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.6
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.5
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.4
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.3
patch
2 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.10.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.7.3
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.2
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.1
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.17.6
patch
| ||
2.6.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.2
patch
2 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.10.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.5.2
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.1
patch
2 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.10.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.5.1
patch
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.4.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.17.5
patch
| ||
1.10.0
minor
2 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.10.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.2.0
minor
3 CVEs
CVE-2026-54297
GHSA-98m9-hrrm-r99r
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A crafted query string such as:
causes Faraday to build a deeply nested Ruby This has been patched in version 2.14.3 and backported to 1.10.6. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 58 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.14.2
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.6
2.14.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33637
GHSA-5rv5-xj5j-3484
May 18, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
0.0
/ 10
None
Network
Low
None
None
Unchanged
None
None
None
Summary
Affected Component
Attacker Profile
Steps to Reproduce
Verification Evidence
Additional External ConfirmationThe issue was also independently reproduced against a public HTTP collector on Faraday
This external confirmation shows the request is not only misbuilt in memory, but is actually dispatched off-host by a real adapter under normal usage. Supporting Materials
ImpactThe direct consequence is off-host request forgery from code paths that believe they are constrained to a fixed base URL. If the connection carries default headers or query parameters, those values are forwarded to the attacker-selected host. Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 30 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.14.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
Fixed in
2.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-25765
GHSA-33mh-2634-fwr2
Feb 09, 2026
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
5.8
/ 10
Medium
Network
Low
None
None
Changed
Low
None
None
ImpactFaraday's This means that if any application passes user-controlled input to Faraday's The Example:
PatchesFaraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected. WorkaroundsNOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading. Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
Example validation:
Affected versions
2.0.0
2.0.1
2.1.0
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
+ 55 more Show less
2.13.2
2.13.3
2.13.4
2.14.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.10.5
2.14.1
References
Updated Sep 10, 2026 · Source: OSV.dev |