PatchSiren

contribsys CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH contribsys CVE published 2026-08-25

CVE-2026-63404

CVE-2026-63404 is a high-severity vulnerability in Faktory, a language-agnostic background job server, that allows a local unprivileged user to hijack the Redis configuration and escalate to root. The vulnerability is due to an insecure temporary file flaw in the embedded Redis bootstrapper, which writes its startup configuration to a fixed, predictable, world-writable path. This issue is fixed in version 1.10.0.

HIGH contribsys CVE published 2026-08-25

CVE-2026-63403

CVE-2026-63403 is an unauthenticated denial of service vulnerability in Faktory server versions prior to 1.10.0. The vulnerability arises from the server's line-based wire protocol, where several command handlers slice or index received lines at fixed offsets without checking for payload presence. Sending bare verbs with no payload triggers a Go slice or index out-of-range panic, terminating the entire Go [truncated]