CVE-2013-7239: Memcached

Medium severity, CVSS 4.8. EPSS: 1.2% chance of exploitation in the next 30 days.

memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending another request with incorrect SASL credentials.

Affected products

  • Memcached Memcached: up to and including 1.4.16; version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; version 1.4.4 only; …

Published 2014-01-13. Last modified 2026-06-17.