yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-47783
Component Overview
Vulnerability Overview
Name
CVE-2026-47783
Source
NVD (
link
)
Debian (
link
)
Description
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
CWEs
CWE-208
Published Date
May 20, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed
Patch
https://github.com/memcached/memcached/compare/1.6.41...1.6.42
Release Notes
https://github.com/memcached/memcached/wiki/ReleaseNotes1642
Release Notes
Analysis
#
Affected Component
Analysis
memcached
Exploitable
Vulnerability Ratings
#
8.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
memcached
buildroot
2025.02.x
1.6.42
Not Affected
memcached
buildroot
master
1.6.42
Not Affected
memcached
openwrt
master
1.6.31-r1
Exploitable
memcached
yocto
kirkstone
1.6.15
Exploitable
memcached
yocto
master
1.6.42
Not Affected