In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by saslserveruserdb_checkpass.
{
"severity": "High",
"cpes": [
"cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:*"
]
}