neo4j
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting neo4j.
- CVE-2026-19869Privilege Escalation via Dropped Field-Level @authentication
- CVE-2026-5423Subscription Authentication Bypass via Unverified connectionParams.jwt
- CVE-2026-14587Unathenticated connection can hold Bolt channel open7.5
- CVE-2026-1471Caching of authentication context
- CVE-2026-1524Auth misconfiguration when multiple providers enabled9.8
- CVE-2026-1497Incorrect privilege assignment in composite databases7.2
- CVE-2026-1337Insufficient escaping of unicode characters in query log5.4
- CVE-2026-1622Unredacted data exposure in query.log
- CVE-2025-12738Enumeration of restricted property value
- CVE-2025-11602Untargeted information leak in Bolt protocol handshake
- CVE-2025-10193Neo4j Cypher MCP server is vulnerable to DNS rebinding attacks
- CVE-2024-34517The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.6.5
- CVE-2023-23926APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml procedure of APOC core plugin prior to version 5.5.0 ...5.9
- CVE-2022-23532neo4j-apoc-procedures is vulnerable to path traversal7.1
- CVE-2022-37423Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.7.5