Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
https://www.couchbase.com/alerts/
https://forums.couchbase.com/tags/security
https://docs.couchbase.com/server/current/release-notes/relnotes.html