Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Memcached

First CVE: Dec 12, 2013Active for: 13 yearsTotal CVEs: 21
61.2
VTI Score
TOP TARGET

Memcached is a widely embedded in-memory caching layer that, despite a single-product footprint, sits deep in the infrastructure of web applications and distributed systems at scale. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, reflecting the memory-unsafe implementation and the high-value target that caching systems present to attackers. The recurring weakness classes—integer overflows, buffer overflows, improper memory-buffer restrictions, and timing-side-channel conditions—are characteristic of a C-based daemon handling untrusted network input without bounds checking. Defenders should treat Memcached instances as high-priority for patching, particularly when exposed to untrusted networks or handling sensitive session or cache data; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
2.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Memcached over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2013
12 years ago
Most Recent CVE
May 20, 2026
65 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1000115HIGH
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that ca
Mar 5, 20187.586NOYES
CVE-2016-8706HIGH
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overf
Jan 6, 20178.162NOYES
CVE-2016-8704CRITICAL
An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to ca
Jan 6, 20179.842NONO
CVE-2011-4971MEDIUM
Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_append_prepend functions in Mem
Dec 12, 20135.038NOYES
CVE-2026-47783HIGH
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_serv
May 20, 20268.137NONO
CVE-2020-10931HIGH
Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.
Mar 24, 20207.535NONO
CVE-2026-47784HIGH
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
May 20, 20268.133NONO
CVE-2016-8705CRITICAL
Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause h
Jan 6, 20179.833NONO
CVE-2023-46853CRITICAL
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
Oct 27, 20239.828NONO
CVE-2019-11596HIGH
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command mes
Apr 29, 20197.526NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
14%
14%
57%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.8%)
Network15 (71.4%)
Unknown5 (23.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (61.9%)
High3 (14.3%)
Unknown5 (23.8%)
User Interaction
None15 (71.4%)
Unknown5 (23.8%)
Required1 (4.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None16 (76.2%)
Unknown5 (23.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
9.5% of CVEs· 98th percentile
Nuclei
1 CVE
4.8% of CVEs· 96th percentile
ExploitDB
1 CVE
4.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Memcached.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Memcached — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Memcached's Products

View all 4 CNAs →

Top CWEs