Junglewise Threat Intelligence

CVE-2026-47784: Memcached timing side channel in SASL authentication

CVE-2026-47784 · Severity: high · CVSS 8.1 · Published 2026-05-20

Technologies: Memcached. Vendors: Memcached.

Executive brief

Memcached is a high-performance memory caching system used to speed up web applications by storing data in RAM. A security flaw in its authentication process could allow an attacker to guess valid usernames and passwords by measuring the time it takes for the system to respond to login attempts. If exploited, this could lead to unauthorized access to the cached data, potentially exposing sensitive user information or allowing an attacker to disrupt service operations.

Technical details

A timing side-channel vulnerability exists in the sasl_server_userdb_checkpass function of memcached before version 1.6.42. The implementation used the standard memcmp() function for username and password comparisons, which returns early upon encountering the first differing byte. Additionally, the authentication logic included an early break when a valid username was found in the password database. These behaviors create measurable timing discrepancies that a remote, unauthenticated attacker can exploit to perform timing attacks to determine valid usernames and eventually recover passwords. The fix, introduced in version 1.6.42, replaces memcmp with a constant-time comparison (safe_memcmp) and ensures the entire password file is scanned regardless of whether a match is found.

Affected products

  • memcached memcached before 1.6.42

Timeline

  • 2026-05-18: patched: Release of version 1.6.42 fixing the issue.
  • 2026-05-20: advisory: CVE-2026-47784 published.

References

Related threats