Browse all 13 CVE security advisories affecting neo4j. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Neo4j serves as a graph database platform primarily used for relationship-based data analysis and complex query processing. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, often stemming from authentication bypass flaws and insecure default configurations. While no major public security incidents have been widely documented, the platform's 10 recorded CVEs highlight potential risks in areas like authentication mechanisms and API security. Its security characteristics include built-in encryption and role-based access controls, though implementations require careful configuration to prevent unauthorized access to sensitive graph data structures.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-14587 | Unathenticated connection can hold Bolt channel open — Enterprise Edition CWE-130 | 5.5 | Medium | 2026-08-05 |
| CVE-2026-1471 | Caching of authentication context — Enterprise edition CWE-863 | 6.5AI | Medium AI | 2026-03-11 |
| CVE-2026-1524 | Auth misconfiguration when multiple providers enabled — Enterprise Edition CWE-863 | 7.2AI | High AI | 2026-03-11 |
| CVE-2026-1497 | Incorrect privilege assignment in composite databases — Enterprise Edition CWE-863 | 9.8AI | Critical AI | 2026-03-11 |
| CVE-2026-1337 | Insufficient escaping of unicode characters in query log — Enterprise Edition CWE-117 | 6.1AI | Medium AI | 2026-02-06 |
| CVE-2026-1622 | Unredacted data exposure in query.log — Enterprise Edition CWE-532 | 3.3AI | Low AI | 2026-02-04 |
| CVE-2025-12738 | Enumeration of restricted property value — Enterprise Edition CWE-200 | 4.3AI | Medium AI | 2026-01-22 |
| CVE-2025-11602 | Untargeted information leak in Bolt protocol handshake — Enterprise Edition CWE-226 | 5.3 | - | 2025-10-31 |
This page lists every published CVE security advisory associated with neo4j. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.