Overview
What is CVE-2026-47784?
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
Vulnerability intelligence
CVE-2026-47784 and is rated High severity with a CVSS score of 8.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.