sync-gatewayGHSA-pqhp-4xfc-hjgq
Couchbase Sync Gateway shows cleartext passwords in redacted and unredacted output
High7.3CVE-2025-52490 · Published Jul 29, 2025 · updated Jun 25, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/couchbase/sync_gateway Go | < 3.2.6 | 3.2.6 |
Details and references
An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-319
- Also known as
- CVE-2025-52490, GO-2026-5550, PYSEC-2025-101
More sync-gateway advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 152022 | SQL Injection in Couchbase Sync Gateway CVE-2019-9039Critical9.8fixed in 2.5.0 | Critical9.8 | 2.5.0 |