CVE-2024-25673: Couchbase Server
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
Affected products
- Couchbase Couchbase Server: from 2.0.0, before 7.2.6 (fixed in 7.2.6); from 7.6.0, before 7.6.2 (fixed in 7.6.2)
Published 2024-09-19. Last modified 2026-06-17.