CVE-2026-63403
- EPSS 0.43%
- Veröffentlicht 25.08.2026 22:17:04
- Zuletzt bearbeitet 09.09.2026 21:09:13
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of service in which a single malformed command crashes the entire process. Its wire protocol is line-based, and s...
CVE-2026-63404
- EPSS 0.15%
- Veröffentlicht 25.08.2026 22:17:04
- Zuletzt bearbeitet 09.09.2026 21:09:13
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to roo...
CVE-2023-37279
- EPSS 0.77%
- Veröffentlicht 20.09.2023 22:15:13
- Zuletzt bearbeitet 21.11.2024 08:11:23
Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can suffer from denial of service by a crafted malicious url query param `days`. The vulnerability is related to how the backend reads ...