CVE-2026-63404 is a high-severity vulnerability in Faktory, a language-agnostic background job server, that allows a local unprivileged user to hijack the Redis configuration and escalate to root. The vulnerability is due to an insecure temporary file flaw in the embedded Redis bootstrapper, which writes its startup configuration to a fixed, predictable, world-writable path. This issue is fixed in version 1.10.0.
CVE-2026-63403 is an unauthenticated denial of service vulnerability in Faktory server versions prior to 1.10.0. The vulnerability arises from the server's line-based wire protocol, where several command handlers slice or index received lines at fixed offsets without checking for payload presence. Sending bare verbs with no payload triggers a Go slice or index out-of-range panic, terminating the entire Go [truncated]