CVE-2026-90698
memcached mcmc Tokenizer proto_text.c try_read_command_asciiauth out-of-bounds
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.
| CWE | CWE-125 CWE-119 |
| Vendor | n/a |
| Product | memcached |
| Published | Sep 14, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a memcached
Be the first to know when new medium vulnerabilities affecting n/a memcached are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / memcached
1.6.41 1.6.42 1.6.43
References
vuldb.com: https://vuldb.com/vuln/403231 vuldb.com: https://vuldb.com/vuln/403231/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90698 vuldb.com: https://vuldb.com/submit/916217 vuldb.com: https://vuldb.com/submit/916219 protectiv.ph: https://protectiv.ph/research/memcached-asciiauth-empty-line-dos github.com: https://github.com/memcached/memcached/commit/af05c9302bba508b736c3da1d5670f63fe8b7db4 github.com: https://github.com/memcached/memcached/releases/tag/1.6.44 github.com: https://github.com/memcached/memcached/
Credits
๐ Ebfe7001d27b27064356271ddfb15d59 (VulDB User)