Neo4j 1.x — End of Life
EOL Critical riskNeo4j 1.x reached end of life on Nov 21, 2014, 4338 days ago, and no longer receives security fixes. The most recent release in this series is 1.9.9. 4 CVEs are tracked for this series, including 1 critical. 4 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Neo4j 2. See Neo4j 2 →
Neo4j 1.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 1.9 | May 21, 2013 | — | Nov 21, 2014 | 1.9.9 | EOL | |
| 1.8 | Sep 28, 2012 | — | Mar 28, 2014 | 1.8.3 | EOL | |
| 1.7 | Apr 18, 2012 | — | Oct 18, 2013 | 1.7.2 | EOL | |
| 1.6 | Jan 22, 2012 | — | Jul 22, 2013 | 1.6.3 | EOL | |
| 1.5 | Nov 9, 2011 | — | Mar 9, 2013 | 1.5.3 | EOL | |
| 1.4 | Jul 8, 2011 | — | Jan 8, 2013 | 1.4.2 | EOL | |
| 1.3 | Apr 12, 2011 | — | Sep 12, 2012 | 1.3.0 | EOL | |
| 1.2 | Dec 29, 2010 | — | Jun 29, 2012 | 1.2.0 | EOL | |
| 1.1 | Jul 30, 2010 | — | Jan 30, 2012 | 1.1.0 | EOL | |
| 1.0 | Feb 23, 2010 | — | Aug 23, 2011 | 1.0.0 | EOL |
CVEs affecting Neo4j 1.x (40)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 1.5 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 1.0 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 1.4 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 1.9 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 1.8 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 1.2 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 1.7 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 1.3 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 1.1 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 1.6 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 1.4 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 1.1 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 1.9 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 1.8 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 1.2 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 1.7 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 1.6 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 1.3 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 1.5 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 1.0 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 1.3 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 1.7 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 1.6 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 1.5 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 1.9 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 1.2 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 1.1 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 1.0 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 1.8 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 1.4 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 1.8 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 1.3 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 1.2 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 1.6 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 1.7 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 1.0 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 1.4 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 1.9 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 1.5 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 1.1 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
Neo4j 1.x is EOL — migrate to Neo4j 2.x
Neo4j 2.x is the next major release. Plan your upgrade before Neo4j 1.x stops receiving security patches.
Add a Neo4j 1 EOL badge to your README
Show your users which Neo4j version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/neo4j/1)Frequently asked questions
Is Neo4j 1 end of life?
Yes. All Neo4j 1.x releases have reached end of life and no longer receive security patches. There are 4 known CVEs affecting Neo4j 1.x, including 1 critical. Migrate to Neo4j 2.x as soon as possible.
What CVEs affect Neo4j 1?
There are 4 CVEs tracked for Neo4j 1.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.
What is the latest Neo4j 1 version?
The latest Neo4j 1.x patch release is 1.9.9, released on October 13, 2014. Always run the latest patch to benefit from all security fixes.
How to migrate from Neo4j 1 to Neo4j 2?
To migrate from Neo4j 1 to Neo4j 2: (1) review the official Neo4j 2 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Neo4j 1 in production?
No. Neo4j 1 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
