CVE-2026-47783

Name
CVE-2026-47783
Description
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed
cve@mitre.org https://github.com/memcached/memcached/compare/1.6.41...1.6.42
cve@mitre.org https://github.com/memcached/memcached/wiki/ReleaseNotes1642

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:* memcached >= None < 1.6.42

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
memcached edge-main 1.6.39-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.38-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.32-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.27-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.26-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.25-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.23-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.22-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.21-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.20-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.19-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.19-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.18-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.17-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached edge-main 1.6.15-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.23-main 1.6.39-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.22-main 1.6.32-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.21-main 1.6.32-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.20-main 1.6.27-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.19-main 1.6.22-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable