In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
References
Configurations
History
21 May 2026, 17:06
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Memcached
Memcached memcached |
|
| References | () https://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed - Patch | |
| References | () https://github.com/memcached/memcached/compare/1.6.41...1.6.42 - Release Notes | |
| References | () https://github.com/memcached/memcached/wiki/ReleaseNotes1642 - Release Notes | |
| CPE | cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:* |
20 May 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-20 07:16
Updated : 2026-05-21 17:06
NVD link : CVE-2026-47784
Mitre link : CVE-2026-47784
CVE.ORG link : CVE-2026-47784
JSON object : View
Products Affected
memcached
- memcached
CWE
CWE-208
Observable Timing Discrepancy
