CVE-2026-47783

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
Configurations

Configuration 1 (hide)

cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:*

History

21 May 2026, 17:06

Type Values Removed Values Added
CPE cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:*
References () https://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed - () https://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed - Patch
References () https://github.com/memcached/memcached/compare/1.6.41...1.6.42 - () https://github.com/memcached/memcached/compare/1.6.41...1.6.42 - Release Notes
References () https://github.com/memcached/memcached/wiki/ReleaseNotes1642 - () https://github.com/memcached/memcached/wiki/ReleaseNotes1642 - Release Notes
First Time Memcached
Memcached memcached

20 May 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-20 07:16

Updated : 2026-05-21 17:06


NVD link : CVE-2026-47783

Mitre link : CVE-2026-47783

CVE.ORG link : CVE-2026-47783


JSON object : View

Products Affected

memcached

  • memcached
CWE
CWE-208

Observable Timing Discrepancy