Our team’s vulnerability disclosures 2021

September 22, 2022

At Faraday, we are part of the open-source community. Our product relies on various open-source projects, and it is released under the GNU General Public License. Fortunately, these practices are becoming more common and, with them, open-source software is increasing its presence in data centers, consumer devices, and applications.

But this can have its drawbacks, too, as this xkcd comic illustrates. In particular, some of the software we use daily does not have security in mind. In many cases, these tools started as small side projects or weekend experiments, and their creators did not foresee the popularity they might achieve in the future. Regardless of why this happens, and after reflecting on this, our research team started a new quest to find and report vulnerabilities in the open-source projects we use every day.

These are the vulnerabilities we’ve disclosed during 2021

CVE-2021–4021: Uncontrolled resource consumption via specially crafted ELF64 binary for MIPS architecture in radare2.

CVE-2021–4022: Segfault when analyzing an ELF64 for HPPA architecture in rizin.

CVE-2021–43814: Heap-based OOB write when parsing dwarf DIE info in Rizin.

CVE-2021–4166: Out-of-bounds Read while loading session in vim.

CVE-2021–4192: Use After Free while loading session in vim.

CVE-2021–4193: Out-of-bounds Read while loading session in vim.

Continue Reading

The latest handpicked blog articles

At Faraday, security has always been at the core of how we operate.  Today, we are proud to  share an important milestone in our journey: achieving  ISO/IEC 27001:2022 certification, the

June 19, 2026

Reverse engineering undocumented processors has traditionally required months of manual work. In this article, Faraday researchers share how a hybrid AI-assisted pipeline recovered a proprietary instruction set architecture, generated a

June 16, 2026

About Faraday Security Faraday is an All-in-One AI-powered offensive security platform that helps organizations validate exposure, prioritize real risk, and make faster, better-informed security decisions. Built for modern security teams,

June 12, 2026

Stay Informed, Subscribe to Our Newsletter

Enter your email and never miss timely alerts and security guidance from the experts at Faraday.

Faraday provides a smarter way for Large Enterprises, MSSPs, and Application Security Teams to get more from their existing security ecosystem.

Headquarters

Research Lab & Dev

Solutions

Open Source

© 2025 Faraday Security. All rights reserved.
Terms and Conditions | Privacy Policy