Overview
What is CVE-2026-47783?
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
Vulnerability intelligence
CVE-2026-47783 and is rated High severity with a CVSS score of 8.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.