Information Exposure Through Timing Discrepancy in memcached - CVE-2026-47784
Published: May 26, 2026
memcached
Detailed vulnerability description
The vulnerability allows a remote user to disclose password information via a timing side channel.
The vulnerability exists due to observable timing discrepancies in sasl_server_userdb_checkpass when comparing SASL password database authentication data. A remote user can send authentication attempts and measure response times to disclose password information via a timing side channel.