← Vulnerability feed

Vulnerability record · CVE-2018-1000115 · published 5 March 2018

CVE-2018-1000115: Memcached UDP amplification enables denial of service

MMemcached · Memcached

Memcached 1.5.5 exposes UDP support on port 11211 that allows insufficient control of network message volume, letting a small spoofed request trigger a very large response. Reported amplification factors reach roughly 1:50,000, making this a potent reflection and amplification vector for volumetric denial of service. The flaw is fixed in 1.5.6 by disabling UDP by default.

7.5 CVSS 3.0 High EPSS 88% · top 0.2% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.0 base score, v2 5.0
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
30References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityHigh CVSS (7.5) and very high EPSS with public exploits, but impact is limited to denial of service and the fix is a straightforward upgrade or disabling UDP.

What it is

Memcached 1.5.5 exposes UDP support on port 11211 that allows insufficient control of network message volume, letting a small spoofed request trigger a very large response. Reported amplification factors reach roughly 1:50,000, making this a potent reflection and amplification vector for volumetric denial of service. The flaw is fixed in 1.5.6 by disabling UDP by default.

Impact

An attacker can direct large floods of amplified traffic at a victim, exhausting bandwidth and causing denial of service. The memcached host itself is abused as a reflector; there is no confidentiality or integrity impact.

Attack surface

Reachable over the network via UDP port 11211 with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed memcached instance with UDP enabled is a candidate reflector.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.88114, 99.759th percentile) and public Exploit-DB entries exist, indicating mature, widely available exploitation tooling.

What to do

  • Upgrade memcached to 1.5.6 or later, which disables UDP by default; apply vendor errata for Red Hat, Ubuntu, Debian and Synology packages.
  • If UDP is not required, disable it explicitly and bind memcached to localhost or trusted interfaces only.
  • Block or rate-limit inbound UDP/11211 at the network edge and prevent spoofed-source UDP from leaving your network.
  • Firewall memcached instances from the public internet; restrict access to application hosts that need it.
  • Monitor for abnormal outbound UDP traffic volumes from memcached hosts.

Detection

  • Alert on inbound UDP traffic to port 11211 from external or unexpected sources.
  • Baseline and monitor outbound UDP packet and byte rates from memcached hosts for amplification spikes.
  • Search logs and configuration management for memcached versions below 1.5.6 or instances with UDP enabled.
  • Correlate large asymmetric UDP flows with memcached hosts to identify reflector participation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://access.redhat.com/errata/RHBA-2018:2140 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1593 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1627 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2331 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2857 Third Party Advisory
https://blogs.akamai.com/2018/03/memcached-fueled-13-tbps-attacks.html Third Party Advisory
https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974 PatchThird Party Advisory
https://github.com/memcached/memcached/issues/348 Issue TrackingThird Party Advisory
https://github.com/memcached/memcached/wiki/ReleaseNotes156 Third Party Advisory
https://twitter.com/dormando/status/968579781729009664 Third Party Advisory
https://usn.ubuntu.com/3588-1/ Third Party Advisory
https://www.debian.org/security/2018/dsa-4218 Third Party Advisory
https://www.exploit-db.com/exploits/44264/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44265/ ExploitThird Party AdvisoryVDB Entry
https://www.synology.com/support/security/Synology_SA_18_07 Third Party Advisory
https://access.redhat.com/errata/RHBA-2018:2140 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1593 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1627 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2331 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2857 Third Party Advisory
https://blogs.akamai.com/2018/03/memcached-fueled-13-tbps-attacks.html Third Party Advisory
https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974 PatchThird Party Advisory
https://github.com/memcached/memcached/issues/348 Issue TrackingThird Party Advisory
https://github.com/memcached/memcached/wiki/ReleaseNotes156 Third Party Advisory
https://twitter.com/dormando/status/968579781729009664 Third Party Advisory
https://usn.ubuntu.com/3588-1/ Third Party Advisory
https://www.debian.org/security/2018/dsa-4218 Third Party Advisory
https://www.exploit-db.com/exploits/44264/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44265/ ExploitThird Party AdvisoryVDB Entry
https://www.synology.com/support/security/Synology_SA_18_07 Third Party Advisory

Track CVE-2018-1000115 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2018-1000115), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.