Skip to main content

Vendor archive

couchbase CVEs

Beta · best-effort

71 CVEs tagged to vendor couchbase10 Critical, 36 High, 25 Medium, 0 Low, 0 Unrated.

CVE-2025-52490

Published Jul 29, 2025

An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49015

Published Jun 18, 2025

The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of h…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56178

Published Jan 27, 2025

An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25673

Published Sep 19, 2024

Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37034

Published Jul 26, 2024

An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43768

Published Mar 27, 2024

An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50437

Published Feb 29, 2024

An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50436

Published Feb 29, 2024

An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49931

Published Feb 29, 2024

An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45874

Published Feb 29, 2024

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43769

Published Feb 29, 2024

An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49338

Published Feb 28, 2024

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45873

Published Feb 28, 2024

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45875

Published Nov 8, 2023

An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25016

Published Feb 6, 2023

Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 71 CVEsPage 1 of 3