Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component. | |
| Title | memcached mcmc Tokenizer proto_text.c try_read_command_asciiauth out-of-bounds | |
| First Time appeared |
Memcached
Memcached memcached |
|
| Weaknesses | CWE-119 CWE-125 |
|
| CPEs | cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Memcached
Memcached memcached |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T08:30:12.665Z
Reserved: 2026-09-13T05:23:49.531Z
Link: CVE-2026-90698
No data.
No data.
No data.
OpenCVE Enrichment
No data.