CVE-2026-47783
EUVD-2026-3106520.05.2026, 07:16
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| memcached | memcached | 𝑥 < 1.6.42 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.6.23-7.el10_2.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.6.9-7.el9_8.1 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| memcached |
| ||||||||||||||||||
| memcached-devel |
|
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| memcached |
| ||
| memcached-debuginfo |
| ||
| memcached-debugsource |
| ||
| memcached-devel |
| ||
| memcached-selinux |
|
References