affected: - package: ecosystem: PyPI name: couchbase purl: pkg:pypi/couchbase ranges: - events: - introduced: '0' - fixed: 3.2.6 type: ECOSYSTEM versions: - '0.10' - '0.11' - 0.11.1 - 0.7.0 - 0.7.1.post1 - 0.7.2 - 0.8.0 - 0.8.1 - 0.8.2 - '0.9' - 1.0.0 - 1.1.0 - 1.2.0 - 1.2.1 - 1.2.2 - 1.2.3 - 1.2.4 - 1.2.5 - 2.0.0 - 2.0.1 - 2.0.2 - 2.0.3 - 2.0.4 - 2.0.5 - 2.0.6 - 2.0.7 - 2.0.8 - 2.0.9 - 2.1.0 - 2.1.1 - 2.1.2 - 2.1.3 - 2.2.0 - 2.2.1 - 2.2.2 - 2.2.3 - 2.2.4 - 2.2.5 - 2.2.6 - 2.3.0 - 2.3.1 - 2.3.2 - 2.3.3 - 2.3.4 - 2.3.5 - 2.4.0 - 2.4.0a1 - 2.4.0a2 - 2.4.0b0 - 2.4.0b2 - 2.4.1 - 2.4.2 - 2.5.0 - 2.5.1 - 2.5.10 - 2.5.11 - 2.5.12 - 2.5.2 - 2.5.3 - 2.5.4 - 2.5.5 - 2.5.6 - 2.5.7 - 2.5.8 - 2.5.9 - 3.0.0 - 3.0.0a2 - 3.0.0a3 - 3.0.0a4 - 3.0.0a5 - 3.0.0a6 - 3.0.0b1 - 3.0.0b2 - 3.0.0b3 - 3.0.1 - 3.0.10 - 3.0.2 - 3.0.2b1 - 3.0.2b2 - 3.0.2b4 - 3.0.2b5 - 3.0.2b6 - 3.0.2b7 - 3.0.2b9 - 3.0.3 - 3.0.3b20 - 3.0.4 - 3.0.4b1 - 3.0.5 - 3.0.6 - 3.0.7 - 3.0.8 - 3.0.9 - 3.1.0 - 3.1.1 - 3.1.2 - 3.1.3 - 3.2.0 - 3.2.1 - 3.2.2 - 3.2.3 - 3.2.4 - 3.2.5 - 3.2.5.dev1 - 3.2.5rc1 aliases: - CVE-2025-52490 details: An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output. id: PYSEC-2025-101 modified: '2026-05-20T09:18:55.694056Z' published: '2025-07-29T20:15:27.870Z' references: - type: ADVISORY url: https://docs.couchbase.com/server/current/release-notes/relnotes.html - type: ADVISORY url: https://forums.couchbase.com/tags/security - type: ADVISORY url: https://www.couchbase.com/alerts/ severity: - score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L type: CVSS_V3