CVE-2025-49015: Medium severity nuget/CouchbaseNetClient vulnerability
The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49015?
CVE-2025-49015 has a medium severity rating due to its potential impact on secure communications.
How do I fix CVE-2025-49015?
To fix CVE-2025-49015, upgrade the Couchbase .NET SDK to version 3.7.1 or later to ensure proper hostname verification.
Which versions of Couchbase .NET SDK are affected by CVE-2025-49015?
CVE-2025-49015 affects all versions of the Couchbase .NET SDK prior to 3.7.1.
What issue does CVE-2025-49015 expose in the Couchbase .NET SDK?
CVE-2025-49015 exposes a vulnerability due to improper hostname verification for TLS certificates, leading to potential man-in-the-middle attacks.
Is it safe to use Couchbase .NET SDK below version 3.7.1 after CVE-2025-49015?
Using Couchbase .NET SDK below version 3.7.1 after CVE-2025-49015 is considered unsafe due to the insufficient hostname verification.