In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by saslserveruserdb_checkpass.
{
"cpes": [
"cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:*"
],
"severity": "High"
}