CVE-2025-52490: Couchbase Sync Gateway

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.

Affected products

  • Couchbase Sync Gateway: before 3.2.6 (fixed in 3.2.6)

Published 2025-07-29. Last modified 2026-06-17.