CVE-2026-19869 is a high-severity vulnerability in the @neo4j/graphql library, affecting versions from 5.2.0 until the patched versions. The vulnerability occurs when both type-level and field-level @authentication rules are present on the same operation type, causing the field-level rule to be silently discarded. This allows clients with a legitimately issued, correctly signed non-admin token to invoke m [truncated]
The Neo4j Bolt modern handshake decoder vulnerability (CVE-2026-14587) is a critical issue that can cause a denial-of-service (DoS) condition. An unauthenticated client can trigger this issue by sending a selected protocol version followed by 32 continuation bytes in the capability mask. This causes the decoder to reset the reader index and wait for more bytes instead of rejecting the protocol message and [truncated]
CVE-2026-1524 describes an SSO edge case in Neo4j Enterprise edition that can lead to unauthorized access when an administrator configures multiple OIDC providers and mixes authorization-capable and authentication-only providers. In that setup, an authentication-only provider may also be treated as providing authorization. The issue matters only when the authentication-only provider carries groups with hi [truncated]
CVE-2026-1471 describes an authentication-context handling issue in Neo4j Enterprise edition versions prior to 2026.01.4. In certain non-default SSO configurations that use the UserInfo endpoint, the system can retain excessive authentication context after a restart, which may cause authenticated users to inherit the context of the first user who signs in after that restart. The issue is rated Low severit [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T16:16:22.650Z and has not been modified since then. This vulnerability affects Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22. The incorrect resolving of namespaces in composite databases can lead to unintended access grants. An admin intending to give a user access to a remote da [truncated]