PatchSiren

neo4j CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH neo4j CVE published 2026-08-18

CVE-2026-19869

CVE-2026-19869 is a high-severity vulnerability in the @neo4j/graphql library, affecting versions from 5.2.0 until the patched versions. The vulnerability occurs when both type-level and field-level @authentication rules are present on the same operation type, causing the field-level rule to be silently discarded. This allows clients with a legitimately issued, correctly signed non-admin token to invoke m [truncated]

MEDIUM neo4j CVE published 2026-08-05

CVE-2026-14587

The Neo4j Bolt modern handshake decoder vulnerability (CVE-2026-14587) is a critical issue that can cause a denial-of-service (DoS) condition. An unauthenticated client can trigger this issue by sending a selected protocol version followed by 32 continuation bytes in the capability mask. This causes the decoder to reset the reader index and wait for more bytes instead of rejecting the protocol message and [truncated]

LOW neo4j CVE published 2026-03-11

CVE-2026-1524

CVE-2026-1524 describes an SSO edge case in Neo4j Enterprise edition that can lead to unauthorized access when an administrator configures multiple OIDC providers and mixes authorization-capable and authentication-only providers. In that setup, an authentication-only provider may also be treated as providing authorization. The issue matters only when the authentication-only provider carries groups with hi [truncated]

LOW Neo4j CVE published 2026-03-11

CVE-2026-1471

CVE-2026-1471 describes an authentication-context handling issue in Neo4j Enterprise edition versions prior to 2026.01.4. In certain non-default SSO configurations that use the UserInfo endpoint, the system can retain excessive authentication context after a restart, which may cause authenticated users to inherit the context of the first user who signs in after that restart. The issue is rated Low severit [truncated]

LOW Neo4j CVE published 2026-03-11

CVE-2026-1497

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T16:16:22.650Z and has not been modified since then. This vulnerability affects Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22. The incorrect resolving of namespaces in composite databases can lead to unintended access grants. An admin intending to give a user access to a remote da [truncated]