memcached vulnerabilities
CVEs whose affected-version data names the memcached package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-90698Medium· 5.3PoCA security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds…
▾ TwilightRed Hat · memcachedEPSS 0.50%via NVD
CVE-2026-47783High· 8.1In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
▾ Twilightmemcached · memcachedEPSS 1.3%via NVD