Couchbase develops a narrowly scoped portfolio centered on its distributed NoSQL database platform and related server, synchronization, and SDK components that serve as datastores and backend infrastructure for applications requiring high availability and scalability. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the sensitivity of database-layer flaws and credential-handling issues in infrastructure software. The exposure recurs across products including Couchbase Server, Sync Gateway, and language SDKs, and is characterized by a durable pattern of authentication, logging, and data-protection weaknesses such as missing authentication for critical functions, cleartext storage and transmission of sensitive information, and inadvertent sensitive-data logging—issues that compound the risk when a database layer is compromised. Defenders should treat database-layer updates from this vendor as high-priority and audit access controls and credential storage in dependent applications; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Couchbase over time
Signals from CVEs in this vendor scope (71 CVEs).
71 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2033HIGH Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: | Apr 14, 2023 | 8.8 | 84 | YES | NO |
CVE-2023-3079HIGH Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: | Jun 5, 2023 | 8.8 | 81 | YES | NO |
CVE-2024-0519HIGH Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secur | Jan 16, 2024 | 8.8 | 69 | YES | NO |
CVE-2020-24719CRITICAL Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are | Nov 12, 2020 | 9.8 | 53 | NO | YES |
CVE-2020-9039CRITICAL Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they | Feb 22, 2020 | 9.8 | 44 | NO | YES |
CVE-2022-32563CRITICAL An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couch | Jun 10, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-35943CRITICAL Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513. | Sep 29, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-11495CRITICAL In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PRNG which results in a small sea | Sep 10, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-15728HIGH Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Admin' role assigned could send a | Aug 24, 2018 | 8.8 | 29 | NO | NO |
CVE-2022-32559CRITICAL An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics. | Jun 14, 2022 | 9.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (71 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Couchbase.
Media articles that mention a CVE ID that affects a product developed by Couchbase — matched by CVE ID, not by vendor name.