What happened
Vertical privilege escalation in CouchDB below 1.7.0/2.1.1 via Erlang-JS JSON parsing differences.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 45019Apache CouchDB - Arbitrary Command Execution (Metasploit)Metasploit2018-07-13VerifiedExploit-DB 44498Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalationr4wd3r2018-04-23VerifiedPoC-in-GitHub · assalielmehdi/CVE-2017-12635Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation★ 10assalielmehdi2019-11-07CandidatePoC-in-GitHub · cyberharsh/Apache-couchdb-CVE-2017-12635★ 1cyberharsh2020-06-19CandidatePoC-in-GitHub · Dungsocool/CVE-2017-12635_36★ 0Dungsocool2026-05-29CandidatePoC-in-GitHub · Darabium/couchdb-exploitThis tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Privilege Escalation via JSON Parsing Bypass | 🔴 Critical | | **CVE-2017-12636** | Remote Code Execution via Query Server | 🔴 Critical |★ 0Darabium2026-08-03CandidateSploitusVertical privilege escalation in CouchDB below 1.7.0/2.1.1 via Erlang-JS JSON parsing differences.KitPloit2026-09-04T03:05:01Candidatekitploit.comVertical privilege escalation in CouchDB below 1.7.0/2.1.1 via Erlang-JS JSON parsing differences.ru2026-09-04T03:05:01CandidateSource timeline
Discovered through Exploit-DBView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.