cvedb.io
CVE-2025-49015
MEDIUM · CVSS 4.9
EPSS exploitation probability: 0%
Published 2025-06-18T14:15:44.870 · Last modified 2026-06-17T09:30:40.673

Summary

The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.

Affected products

couchbase — .net_sdk

Does this affect you?

Add your gear to cvedb and we'll alert you only when couchbase ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.