Couchbase

    Dashboard / Vendors

    Products: 7
    Vulnerabilities: 71
    Known Exploited: 0
    10
    Critical Level Threats
    36
    High Level Threats
    25
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-52490

    An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.

    Last Modified: Aug 06, 2025
    Published: Jul 29, 2025

    CVE-2025-49015

    The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.

    Last Modified: Jul 09, 2025
    Published: Jun 18, 2025

    CVE-2025-46619

    A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.

    Last Modified: May 13, 2025
    Published: Apr 30, 2025

    CVE-2024-56178

    An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role.

    Last Modified: Apr 18, 2025
    Published: Jan 27, 2025

    CVE-2024-25673

    Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.

    Last Modified: Mar 19, 2025
    Published: Sep 19, 2024
    Items Per Page
    Couchbase Vulnerabilities & Security CVEs | CVE-DB