Skip to content
Threat Feed
medium advisory

Memcached Denial of Service Vulnerabilities

Memcached versions prior to 1.4.33 are susceptible to remote, unauthenticated denial-of-service attacks due to improper request handling of specific commands.

CVE search metadata

CVE search record: CVE-2016-8704. Severity: critical. CVSS: 9.8. EPSS: 23.17%. KEV: no. Product: Memcached. Brief: Memcached Denial of Service Vulnerabilities. Brief link: https://feed.craftedsignal.io/briefs/2026-09-memcached-dos/

CVE search record: CVE-2016-8705. Severity: critical. CVSS: 9.8. EPSS: 19.85%. KEV: no. Product: Memcached. Brief: Memcached Denial of Service Vulnerabilities. Brief link: https://feed.craftedsignal.io/briefs/2026-09-memcached-dos/

Memcached versions earlier than 1.4.33 contain vulnerabilities (CVE-2016-8704, CVE-2016-8705) that allow an unauthenticated, remote attacker to trigger a denial-of-service condition. These flaws stem from improper input handling during specific memory operations and request processing. By sending specially crafted packets to the memcached service, an attacker can induce resource exhaustion or memory corruption, resulting in an immediate crash of the service. This vulnerability is significant for organizations relying on memcached for high-performance caching in web architectures, as a successful exploit causes immediate service disruption and potential loss of cached data.

Impact

Successful exploitation results in the unavailability of the memcached service. Because memcached is frequently used to offload database