Skip to content
Couchbase Sync GatewayGHSA-g622-r636-qfqh

SQL Injection in Couchbase Sync Gateway

Critical9.8CVE-2019-9039 · Published Feb 15, 2022 · updated Nov 8, 2023

The Couchbase Sync Gateway 2.1.2 in combination with a Couchbase Server is affected by a previously undisclosed N1QL-injection vulnerability in the REST API. An attacker with access to the public REST API can insert additional N1QL statements through the parameters ?startkey? and ?endkey? of the ?_all_docs? endpoint.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/couchbase/sync_gateway
Go
< 2.5.02.5.0
Details and references

More Couchbase Sync Gateway advisories

All Couchbase Sync Gateway
Advisory
Couchbase Sync Gateway shows cleartext passwords in redacted and unredacted output
High7.3Jul 29, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.