Sync gateway
This hub aggregates every CVE we track for Sync gateway, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
2
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 5 most recently published vulnerabilities affecting Sync gateway.
- CVE-2025-52490An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.7.3
- CVE-2022-32563An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When...9.8
- CVE-2021-43963An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write data in Couchbase Server were insecurely being stored in the metadata within syn...8.1
- CVE-2020-9041In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are vulnerable to the Slowloris denial-of-service attack bec...7.5
- CVE-2019-9039In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL funct...9.8
Product normalization is registry-driven with AI assist and human review. How it works