Home

Description

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

PUBLISHED Reserved 2026-05-20 | Published 2026-05-20 | Updated 2026-05-20 | Assigner mitre




HIGH: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-208 Observable Timing Discrepancy

Product status

Default status
unaffected

Any version before 1.6.42
affected

References

github.com/...ommit/d13f282b4bce33a9c33b8a1bbf07f12114160fed

github.com/memcached/memcached/compare/1.6.41...1.6.42

github.com/memcached/memcached/wiki/ReleaseNotes1642

cve.org (CVE-2026-47784)

nvd.nist.gov (CVE-2026-47784)

Download JSON