memcached vulnerability

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

Published 20 May 2026Updated 18 Sep 20268 sources
CVSS 8.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.