Skip to content
sync-gatewayGHSA-pqhp-4xfc-hjgq

Couchbase Sync Gateway shows cleartext passwords in redacted and unredacted output

High7.3CVE-2025-52490 · Published Jul 29, 2025 · updated Jun 25, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/couchbase/sync_gateway
Go
< 3.2.63.2.6
Details and references

An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-319
Also known as
CVE-2025-52490, GO-2026-5550, PYSEC-2025-101

More sync-gateway advisories

All
DateAdvisory
Feb 152022SQL Injection in Couchbase Sync Gateway
CVE-2019-9039Critical9.8fixed in 2.5.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.