MEDIUM4.9
GHSA-px2c-r924-mwcc
Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificates
Details
The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/CouchbaseNetClient
Introduced in:
0No fixed version published yet for CouchbaseNetClient (nuget). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-49015[ADVISORY]
- https://github.com/couchbase/couchbase-net-client/commit/04d1679b2178f922036be6e595b3d91f972c5ba3[WEB]
- https://docs.couchbase.com/server/current/release-notes/relnotes.html[WEB]
- https://forums.couchbase.com/tags/security[WEB]
- https://github.com/couchbase/couchbase-net-client[PACKAGE]
- https://www.couchbase.com/alerts[WEB]