CVE Tools

Couchbase

51 CVEs tracked since 2019. Since Sep 2019, none of them reached CISA KEV.

Couchbase CVEs per month

Sep 2019 to Feb 2024. Point at a month, or focus the strip and use the arrow keys.
Couchbase CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2019-0970
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-0630
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-0560
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-0930
2021-10null or fewer
2021-1120
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06120
2022-0740
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-0230
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02110

Products

The products that kept showing up in Couchbase's monthly top three, with their CVEs summed over those months.

  1. Couchbase Server489 months
  2. Sync Gateway22 months
  3. Bleve11 month
  4. Couchbase Server Java Sdk11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Couchbase.

  1. CVE-2025-52490An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.7.3
  2. CVE-2025-49015The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a ...4.9
  3. CVE-2025-46619A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of...7.6
  4. CVE-2024-56178An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role.6.5
  5. CVE-2024-25673Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.6.1
  6. CVE-2024-37034An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link ...5.9
  7. CVE-2023-43768An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands.7.5
  8. CVE-2024-23302Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.7.5
  9. CVE-2023-50437An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.8.6
  10. CVE-2023-50436An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.5.3
  11. CVE-2023-49932An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.5.4
  12. CVE-2023-49930An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.9.8
  13. CVE-2023-49338Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.7.5
  14. CVE-2023-49931An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.9.8
  15. CVE-2023-43769An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.6.3

The record

Peak rank
#51 in Sep 2019
Busiest month shown
Jun 2022, 12 CVEs
Months with a KEV entry
0 since Sep 2019
Monthly snapshots
9 since 2019
Couchbase's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store