๐Ÿ” CVE Alert

CVE-2026-90698

MEDIUM 5.3

memcached mcmc Tokenizer proto_text.c try_read_command_asciiauth out-of-bounds

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.

CWE CWE-125 CWE-119
Vendor n/a
Product memcached
Published Sep 14, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for n/a memcached

Be the first to know when new medium vulnerabilities affecting n/a memcached are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / memcached
1.6.41 1.6.42 1.6.43

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/403231 vuldb.com: https://vuldb.com/vuln/403231/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90698 vuldb.com: https://vuldb.com/submit/916217 vuldb.com: https://vuldb.com/submit/916219 protectiv.ph: https://protectiv.ph/research/memcached-asciiauth-empty-line-dos github.com: https://github.com/memcached/memcached/commit/af05c9302bba508b736c3da1d5670f63fe8b7db4 github.com: https://github.com/memcached/memcached/releases/tag/1.6.44 github.com: https://github.com/memcached/memcached/

Credits

๐Ÿ” Ebfe7001d27b27064356271ddfb15d59 (VulDB User)