In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
References
Configurations
History
No history.
Information
Published : 2026-05-20 07:16
Updated : 2026-08-17 12:18
NVD link : CVE-2026-47783
Mitre link : CVE-2026-47783
CVE.ORG link : CVE-2026-47783
JSON object : View
Products Affected
memcached
- memcached
CWE
CWE-208
Observable Timing Discrepancy
