Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47783

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

A flaw was found in memcached. A remote attacker can exploit a timing side channel during Simple Authentication and Security Layer (SASL) password database authentication. This vulnerability allows an attacker to observe subtle timing differences, which could be used to enumerate valid usernames.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6memcachedAffected
Red Hat Enterprise Linux 7memcachedAffected
Red Hat Enterprise Linux 8memcachedAffected
Red Hat Enterprise Linux 10memcachedFixedRHSA-2026:2784222.06.2026
Red Hat Enterprise Linux 9memcachedFixedRHSA-2026:2786222.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2480089memcached: memcached: Username enumeration via timing side channel

EPSS

Процентиль: 67%
0.01264
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
2 месяца назад

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

CVSS3: 8.1
nvd
2 месяца назад

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

CVSS3: 8.1
msrc
2 месяца назад

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

CVSS3: 8.1
debian
2 месяца назад

In memcached before 1.6.42, username data for SASL password database a ...

rocky
около 1 месяца назад

Important: memcached security update

EPSS

Процентиль: 67%
0.01264
Низкий

8.1 High

CVSS3