CVE-2025-49015
Last modified
CVE-2025-49015 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Couchbase | .Net Sdk | <= 3.7.1 |
References
- https://forums.couchbase.com/tags/securityIssue Tracking
- https://www.couchbase.com/alerts/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-49015?
How severe is CVE-2025-49015?
How do I fix CVE-2025-49015?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4901A vulnerability classified as problematic was found in D-Lin…6.5
- CVE-2025-49010OpenSC is an open source smart card tools and middleware. Pr…6.8
- CVE-2025-49011SpiceDB is an open source database for storing and querying …5.3
- CVE-2025-49012Himmelblau is an interoperability suite for Microsoft Azure …5.4
- CVE-2025-49013WilderForge is a Wildermyth coremodding API. A critical vuln…9.9
- CVE-2025-49014jq is a command-line JSON processor. In version 1.8.0 a heap…5.5
- CVE-2025-4902A vulnerability, which was classified as problematic, has be…7.5
- CVE-2025-49028Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail…7.1
- CVE-2025-49029Improper Control of Generation of Code ('Code Injection') vu…9.1
- CVE-2025-4903A vulnerability, which was classified as critical, was found…7.5
- CVE-2025-49031Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-49032Improper Neutralization of Input During Web Page Generation …6.5
Are you affected by CVE-2025-49015?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
