Neo4j 1.x — End of Life

EOL Critical risk
EOL: Nov 21, 201410 releases in this series4 CVEs

Neo4j 1.x reached end of life on Nov 21, 2014, 4338 days ago, and no longer receives security fixes. The most recent release in this series is 1.9.9. 4 CVEs are tracked for this series, including 1 critical. 4 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Neo4j 2. See Neo4j 2 →

Neo4j 1.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
1.9May 21, 2013—Nov 21, 20141.9.9EOL
1.8Sep 28, 2012—Mar 28, 20141.8.3EOL
1.7Apr 18, 2012—Oct 18, 20131.7.2EOL
1.6Jan 22, 2012—Jul 22, 20131.6.3EOL
1.5Nov 9, 2011—Mar 9, 20131.5.3EOL
1.4Jul 8, 2011—Jan 8, 20131.4.2EOL
1.3Apr 12, 2011—Sep 12, 20121.3.0EOL
1.2Dec 29, 2010—Jun 29, 20121.2.0EOL
1.1Jul 30, 2010—Jan 30, 20121.1.0EOL
1.0Feb 23, 2010—Aug 23, 20111.0.0EOL

CVEs affecting Neo4j 1.x (40)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-1524CRITICAL9.80.31%—1.5An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—1.0An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—1.4An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—1.9An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—1.8An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—1.2An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—1.7An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—1.3An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—1.1An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—1.6An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—1.4Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—1.1Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—1.9Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—1.8Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—1.2Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—1.7Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—1.6Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—1.3Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—1.5Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—1.0Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—1.3Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—1.7Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—1.6Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—1.5Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—1.9Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—1.2Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—1.1Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—1.0Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—1.8Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—1.4Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1337MEDIUM5.40.24%—1.8Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—1.3Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—1.2Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—1.6Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—1.7Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—1.0Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—1.4Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—1.9Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—1.5Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—1.1Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026

Neo4j 1.x is EOL — migrate to Neo4j 2.x

Neo4j 2.x is the next major release. Plan your upgrade before Neo4j 1.x stops receiving security patches.

See Neo4j 2.x

Add a Neo4j 1 EOL badge to your README

Show your users which Neo4j version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Neo4j 1 EOL status
[![Neo4j 1 EOL status](https://eolcanary.com/badge/neo4j/1.svg)](https://eolcanary.com/explore/neo4j/1)

Frequently asked questions

Is Neo4j 1 end of life?

Yes. All Neo4j 1.x releases have reached end of life and no longer receive security patches. There are 4 known CVEs affecting Neo4j 1.x, including 1 critical. Migrate to Neo4j 2.x as soon as possible.

What CVEs affect Neo4j 1?

There are 4 CVEs tracked for Neo4j 1.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.

What is the latest Neo4j 1 version?

The latest Neo4j 1.x patch release is 1.9.9, released on October 13, 2014. Always run the latest patch to benefit from all security fixes.

How to migrate from Neo4j 1 to Neo4j 2?

To migrate from Neo4j 1 to Neo4j 2: (1) review the official Neo4j 2 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Neo4j 1 in production?

No. Neo4j 1 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA