VYPR

Faktory

by Contribsys

Source repositories

CVEs (3)

  • CVE-2026-63403HigAug 25, 2026
    risk 0.50cvss —epss 0.00

    Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of service in which a single malformed command crashes the entire process. Its wire protocol is line-based, and several command handlers slice…

  • CVE-2023-37279HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can suffer from denial of service by a crafted malicious url query param `days`. The vulnerability is related to how the backend reads the `days` URL query…

  • CVE-2026-63404HigAug 25, 2026
    risk 0.40cvss —epss 0.00

    Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It writes its startup…