Neo4j
cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:*:*
- >= 5.26.0, <= 5.26.14
- >= 2025.1.0, <= 2025.10.0
A potential information leak vulnerability has been identified in the Bolt protocol handshake of Neo4j Community and Enterprise editions. This vulnerability affects versions 5.26.0 to 5.26.14 and 2025.1.0 to 2025.10.0. It allows an attacker to obtain one byte of information from previous connections, without any control over the leaked information in server responses.
Exploitation of this vulnerability could lead to an unauthorized information leak, allowing an attacker to retrieve sensitive data from previous connections.
Users are advised to upgrade to Neo4j versions 5.26.15 or 2025.10.1 and above, where this issue has been fixed. This vulnerability is not applicable to Neo4j AuraDB, the fully managed cloud service.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.