In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by saslserveruserdb_checkpass.
{
"cpes": [
"cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:*"
],
"severity": "High"
}