CVE-2022-26635: Critical severity memcached vulnerability
Published Apr 5, 2022
·Updated
PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection.
Affected Software
1 affected component
PHP Memcached<=2.2.0
Event History
Apr 5, 2022
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-26635.
2
What is the severity level of CVE-2022-26635?
The severity level of CVE-2022-26635 is critical (9.8).
3
Which versions of PHP-Memcached are affected by CVE-2022-26635?
Versions 2.2.0 and below of PHP-Memcached are affected by CVE-2022-26635.
4
What is the impact of CVE-2022-26635?
CVE-2022-26635 allows attackers to execute CLRF injection.
5
Is there a fix available for CVE-2022-26635?
At the moment, there is no available fix for CVE-2022-26635. It is recommended to update to a version of PHP-Memcached that is not affected.