Memcached is a widely embedded in-memory caching layer that, despite a single-product footprint, sits deep in the infrastructure of web applications and distributed systems at scale. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, reflecting the memory-unsafe implementation and the high-value target that caching systems present to attackers. The recurring weakness classes—integer overflows, buffer overflows, improper memory-buffer restrictions, and timing-side-channel conditions—are characteristic of a C-based daemon handling untrusted network input without bounds checking. Defenders should treat Memcached instances as high-priority for patching, particularly when exposed to untrusted networks or handling sensitive session or cache data; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Memcached over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000115HIGH Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that ca | Mar 5, 2018 | 7.5 | 86 | NO | YES |
CVE-2016-8706HIGH An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overf | Jan 6, 2017 | 8.1 | 62 | NO | YES |
CVE-2016-8704CRITICAL An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to ca | Jan 6, 2017 | 9.8 | 42 | NO | NO |
CVE-2011-4971MEDIUM Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_append_prepend functions in Mem | Dec 12, 2013 | 5.0 | 38 | NO | YES |
CVE-2026-47783HIGH In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_serv | May 20, 2026 | 8.1 | 37 | NO | NO |
CVE-2020-10931HIGH Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c. | Mar 24, 2020 | 7.5 | 35 | NO | NO |
CVE-2026-47784HIGH In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. | May 20, 2026 | 8.1 | 33 | NO | NO |
CVE-2016-8705CRITICAL Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause h | Jan 6, 2017 | 9.8 | 33 | NO | NO |
CVE-2023-46853CRITICAL In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n. | Oct 27, 2023 | 9.8 | 28 | NO | NO |
CVE-2019-11596HIGH In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command mes | Apr 29, 2019 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Memcached.
Media articles that mention a CVE ID that affects a product developed by Memcached — matched by CVE ID, not by vendor name.