{"api_version":"v1","generated_at":"2026-10-07T13:45:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-lostisland-faraday-cb331d610ea7","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/faraday","name":"faraday","next_cursor":null,"observations":[{"affected":">= 1.0.0, < 1.10.6; >= 2.0.0.alpha.pre.1, < 2.14.3","affected_versions_present":true,"cve_id":"CVE-2026-54297","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54297","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-14T12:04:27.246Z","patch_url":"https://github.com/lostisland/faraday/security/advisories/GHSA-98m9-hrrm-r99r","primary_source":"","published":"2026-06-24T15:50:08.949Z"},{"affected":">= 2.0.0, <= 2.14.2","affected_versions_present":true,"cve_id":"CVE-2026-33637","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33637","fixed":"2.14.3.","last_modified":"2026-05-19T18:37:22.100Z","patch_url":"https://github.com/lostisland/faraday/security/advisories/GHSA-5rv5-xj5j-3484","primary_source":"","published":"2026-05-19T17:44:42.557Z"},{"affected":"< 2.14.1","affected_versions_present":true,"cve_id":"CVE-2026-25765","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25765","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-10T15:59:26.645Z","patch_url":"https://github.com/lostisland/faraday/commit/a6d3a3a0bf59c2ab307d0abd91bc126aef5561bc","primary_source":"","published":"2026-02-09T20:30:58.774Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"lostisland"}}
