Netlas.io[verified]@Netlas_ioDisclosure
Two new Memcached SASL vulnerabilities (CVE‑2026‑47783 & CVE‑2026‑47784) expose a timing side‑channel that allows attackers to enumerate valid usernames and guess passwords, rated at a CVSS score of 8.1.
yousukezan[verified]@yousukezanDisclosure
Two high‑severity Memcached SASL timing‑attack vulnerabilities (CVE‑2026‑47783/84) were disclosed; they allow credential enumeration by measuring response latency, and both are fixed in Memcached 1.6.42 with an update recommendation.
kokumօtօ[verified]@__kokumotoPatch
The post discloses Memcached SASL side‑channel vulnerability CVE‑2026‑47783/84 and confirms that version 1.6.42 includes a patch.
DFIR Lab[verified]@DFIR_LabPatch
CVE-2026-47783 is a timing side‑channel flaw in memcached 1.6.42‑under‑, enabling username enumeration via SASL authentication; patching to 1.6.42+ resolves the issue.
VulnTracker[verified]@vuln_trackerDisclosure
The article announces two Memcached SASL vulnerabilities (CVE-2026-47783 and CVE-2026-47784) that allow attackers to enumerate usernames and brute‑force credentials, with 8,539 affected instances worldwide.
elhacker.NET@elhackernetDisclosure
An article announces that CVE‑2026‑47783 is a critical Memcached SASL vulnerability permitting attackers to infer valid usernames; no evidence of a PoC, exploit code, patch, or active attacks is provided.
Open Source Security mailing list@oss_securityDisclosure
Memcached versions prior to 1.6.42 are affected by CVE-2026-47783 and CVE-2026-47784, which involve timing side channels during SASL username/password authentication.
iototsecnews@iototsecnewsDisclosure
The article reveals a timing‑based SASL authentication flaw in Memcached (CVE‑2026‑47783) that allows attackers to infer valid usernames, but no PoC, exploit, or patch details are provided.