Memcached released version 1.6.42 to fix two high-severity SASL authentication timing side-channel vulnerabilities affecting versions prior to 1.6.42. The flaws, tracked as CVE-2026-47783 and CVE-2026-47784, can let attackers infer valid usernames and extract password information through response-time analysis. According to the disclosures, one bug leaked username-related information because authentication logic stopped searching once it found a valid user, while the other exposed password-related information because password checks relied on memcmp, enabling byte-by-byte timing differences.
The maintainers described 1.6.42 as a major security-focused release and urged users to upgrade immediately. In addition to the SASL fixes, the release addressed a broad set of security and stability problems, including memory corruption risks, crashes, signed integer overflow in binary protocol body-length handling, authentication reload races, malformed-input handling issues, proxy parsing flaws, extstore and slab reassignment bugs, and other denial-of-service conditions. The exposure is especially relevant where Memcached is reachable from untrusted networks, cloud deployments, or loosely segmented microservices environments, where the timing leaks could aid reconnaissance, brute-force attempts, or credential-stuffing activity.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-19, an oss-sec post reported that MITRE had assigned CVE-2026-47783 and CVE-2026-47784 to two timing side-channel flaws affecting Memcached versions before 1.6.42. The disclosure explained that one flaw leaks username-related information during SASL authentication and the other can leak password information due to use of memcmp, and noted both were fixed in 1.6.42.
Memcached released version 1.6.42 on 2026-05-18 as a major security-focused update and strongly advised users to upgrade. The release fixed numerous security and stability issues across SASL authentication, binary protocol handling, proxy code, extstore behavior, slab reassignment, and related components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourceseclists.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.