PT-2026-42109 · Memcached · Memcached

Published

2026-05-20

·

Updated

2026-05-20

·

CVE-2026-47783

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl server userdb checkpass.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-47783

Affected Products

Memcached