Where
-Infinity
0

Vendor Risk Score

See how memcached compares to other vendors in security performance

View Risk Score →
Severity
9.8
Integer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Multiple integer overflows in processbinupdate function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

1 / 2
First published (updated )
Severity
9.8
Integer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An integer overflow in the processbinappendprepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

1 / 2
Source: MITRE
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.

First published (updated )
Severity
8.1
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by saslserveruserdbcheckpass.

1 / 2
Source: MITRE
First published (updated )
Severity
8.1
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by saslserveruserdbcheckpass.

1 / 2
Source: MITRE
First published (updated )
Severity
8.1
Integer Overflow
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

An integer overflow in processbinsaslauth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

First published (updated )
Severity
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Last updated 25 August 2025

1 / 2
Source: Ubuntu
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to tryreadcommandbinary in memcached.c.

First published (updated )
Severity
7.5
Null Pointer Dereference
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru tempttl" commands. This causes a denial of service when parsing crafted lru command messages in processlrucommand in memcached.c.

1 / 2
Source: Ubuntu
First published (updated )
Severity
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Last updated 25 August 2025

1 / 2
Source: Ubuntu
First published (updated )
Severity
7.5
Integer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A flaw was found in memcached version prior to 1.4.37. It contains an Integer Overflow vulnerability in items.c:itemfree() that can result in resource leaks or data corruption, deadlocks and crashes due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service.

References: https://github.com/memcached/memcached/issues/271 https://github.com/memcached/memcached/wiki/ReleaseNotes1437

Upstream Patch: https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92d1bae00

1 / 3
Source: Red Hat
First published (updated )
Severity
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Last updated 25 August 2025

1 / 3
Source: Ubuntu
First published (updated )
Severity
7.5
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.

First published (updated )
Severity
7.5
Command Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.

First published (updated )
Severity
7

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by saslserveruserdbcheckpass.

First published (updated )
Severity
5.5
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Multiple integer signedness errors in the (1) processbinsaslauth, (2) processbincompletesaslauth, (3) processbinupdate, and (4) processbinappendprepend functions in Memcached 1.4.5 and earlier allow remote attackers to cause a denial of service (crash) via a large body length value in a packet.

First published (updated )
Severity
4.8
AV:A/AC:L/Au:N/C:P/I:P/A:N

memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending another request with incorrect SASL credentials.

First published (updated )
Severity
1.8
Buffer Overflow
AV:A/AC:H/Au:N/C:N/I:N/A:P

Description of problem:

When run with "-vv", on receipt of a binary-protocol deletion request, memcached prints out the key to be deleted in a way that can lead to a buffer overrun and crash.

Version-Release number of selected component (if applicable):

1.4.4, although this currently affects all later versions.

How reproducible:

Run memcached with "-vv", use memrm to send deletion requests and observe output.

Steps to Reproduce:

1. memcached -p 12345 -vv 2>&1 | grep '^Deleting' 2. memrm --servers localhost:12345 --binary ABCDEF xyz 3. Check the output from memcached.

Actual results:

[jsowden:~] $ memcached -p 2300 -m 64 -c 1024 -r -vv 2>&1 | grep 'Deleting' Deleting ABCDEF Deleting xyzDEF

Expected results:

[jsowden:~] $ memcached -p 2300 -m 64 -c 1024 -r -vv 2>&1 | grep 'Deleting' Deleting ABCDEF Deleting xyz

Additional info:

I've opened a bug report upstream: https://code.google.com/p/memcached/issues/detail?id=306

1 / 2
Source: Red Hat
First published (updated )
Severity
1.8
Buffer Overflow
AV:A/AC:H/Au:N/C:N/I:N/A:P

memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggers an "unbounded key print" during logging, related to an issue that was "quickly grepped out of the source tree," a different vulnerability than CVE-2013-0179 and CVE-2013-7290.

First published (updated )
Severity
1.8
Buffer Overflow
AV:A/AC:H/Au:N/C:N/I:N/A:P

The doitemget function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.

First published (updated )
Severity
1
Buffer Overflow

Description of problem:

When run with "-vv", on receipt of a binary-protocol deletion request, memcached prints out the key to be deleted in a way that can lead to a buffer overrun and crash.

Version-Release number of selected component (if applicable):

1.4.4, although this currently affects all later versions.

How reproducible:

Run memcached with "-vv", use memrm to send deletion requests and observe output.

Steps to Reproduce:

1. memcached -p 12345 -vv 2>&1 | grep '^Deleting' 2. memrm --servers localhost:12345 --binary ABCDEF xyz 3. Check the output from memcached.

Actual results:

[jsowden:~] $ memcached -p 2300 -m 64 -c 1024 -r -vv 2>&1 | grep 'Deleting' Deleting ABCDEF Deleting xyzDEF

Expected results:

[jsowden:~] $ memcached -p 2300 -m 64 -c 1024 -r -vv 2>&1 | grep 'Deleting' Deleting ABCDEF Deleting xyz

Additional info:

I've opened a bug report upstream: https://code.google.com/p/memcached/issues/detail?id=306

First published (updated )

Latest version: 1.6.45

First published (updated )

Latest version: 1.6.45

First published (updated )
EOL
Mar 9, 2020

End of life: 3/9/2020, Latest version: 1.5.22

First published (updated )
EOL
Mar 9, 2020

End of life: 3/9/2020, Latest version: 1.5.22

First published (updated )
EOL
Jul 21, 2017

End of life: 7/21/2017, Latest version: 1.4.39

First published (updated )
EOL
Jul 21, 2017

End of life: 7/21/2017, Latest version: 1.4.39

First published (updated )

https://github.com/memcached/memcached/wiki/ReleaseNotes1642 reveals: Memcached 1.6.42 Release Notes

Date: 2026-5-18

Download -------- http://www.memcached.org/files/memcached-1.6.42.tar.gz

Overview -------- This is a major security focused release. Nearly all of the fixes are security related for issues that can cause memory corruption, crashes, and so on.

If you submitted a security report that ended up being value, you are credited in the commit history.

If you submitted a security report and do not see it here, it was either not a security bug or I missed it.

Due to the very high volume of security reports in this round I did not give them the individual scrutiny that I typically do: if there was a clear bug, it was fixed, but no effort was made to validate the potential impact of the bug.

Most of the these bugs look extremely obscure, and are impossible to trigger without convoluted configurations. This does not apply to all of the bugs: if memcached can be accessed easily by an attacker it can be crashed.

Similarly I have not created CVE's for any of these as that requires understanding the severity of each bug. In most cases these submissions vastly overstated the severity of the bug. I leave it up to the submitters to request their own CVE's if they wish.

Upgrading is strongly advised, regardless. Thanks to everyone who submitted reports and for your patience in allowing me to collect the fixes all at once.

Fixes ----- - vendor: Instructively warn if vendor blob missing - proxy: fix write length in extstore miss - Fix timing side-channel in SASL password database authentication - proto: fix signed overflow in bodylen for binprot - proxy: fix underflow with 0 length values - auth: fix data race during reload - auth: fix crash when given huge token - proto: fix crash in binary protocol - core: fix crashes from slabs reassign - proxy: check result of buffer parse in matchres - proxy: fix memory underread when nulling requests - update data block protocol description to no longer reference obsolete S flag

New Features ------------ None.

Contributors ------------ The following people contributed to this release since 1.6.41.

Note that this is based on who contributed changes, not how they were done. In many cases, a code snippet on the mailing list or a bug report ended up as a commit with your name on it.

Note that this is just a summary of how many changes each person made which doesn't necessarily reflect how significant each change was. For details on what led up into a branch, either grab the git repo and look at the output of git log 1.6.41..1.6.42 or use a web view.

- Repo list: https://github.com/memcached/memcached/wiki/DevelopmentRepos - Web View: http://github.com/memcached/memcached/commits/1.6.42

8 dormando 2 Bujna, Igor 1 Alec Stewart 1 Sarthak Munshi

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203