In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by saslserveruserdb_checkpass.
{
"severity": "High",
"cpes": [
"cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:*"
]
}