Executive brief
Memcached is a high-performance memory caching system used to speed up web applications by storing data in RAM. A security flaw in its authentication process allows an attacker to distinguish between valid and invalid usernames by measuring how long the server takes to respond. This could allow an unauthorized user to guess valid account names or passwords, potentially leading to unauthorized access to cached data or administrative functions.
Technical details
A timing side-channel vulnerability exists in the sasl_server_userdb_checkpass function of memcached. The implementation used an early-exit loop when a valid username was found and utilized the non-constant-time memcmp() function for password verification. These behaviors create measurable timing discrepancies that allow a remote, unauthenticated attacker to perform username enumeration and potentially recover password bytes through timing analysis. The issue was addressed in version 1.6.42 by replacing memcmp() with a constant-time safe_memcmp() and ensuring the entire password file is scanned regardless of whether a match is found.
Affected products
- memcached memcached before 1.6.42
Timeline
- 2026-05-18: patched: Fixed in memcached version 1.6.42
- 2026-05-20: disclosed: CVE-2026-47783 published