Review reviewHigh

CVE-2026-54297

lostisland faraday, Red Hat 3scale API Management Platform 2, Red Hat Satellite 6

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the...

CVSS
7.5
EPSS
0.43%
35.5% percentile
CISA KEV
Not listed
Published
2026.06.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.43%
Technical severityCVSS 7.5

Vulnerability overview

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the...

Affected product and versions

Product
lostisland faraday, Red Hat 3scale API Management Platform 2, Red Hat Satellite 6
Affected versions
>= >= 1.0.0, < 1.10.6, >= >= 2.0.0.alpha.pre.1, < 2.14.3, >= 1.0.0 < 1.10.6, >= 2.0.0 < 2.14.3
Fixed versions
1.10.6, 2.14.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that lostisland faraday, Red Hat 3scale API Management Platform 2, Red Hat Satellite 6 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-674, CWE-770
CVE-2026-54297 — lostisland faraday, Red Hat 3scale API Management Platform 2, Red Hat Satellite 6 | SECUFOCUS NOW