Neo4j 4.x — End of Life
EOL Critical riskNeo4j 4.x reached end of life on Nov 30, 2025, 311 days ago, and no longer receives security fixes. The most recent release in this series is 4.4.48. 4 CVEs are tracked for this series, including 1 critical. 4 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Neo4j 5. See Neo4j 5 →
Neo4j 4.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 4.4LTS | Dec 2, 2021 | — | Nov 30, 2025 | 4.4.48 | EOL | |
| 4.3 | Jun 17, 2021 | — | Dec 16, 2022 | 4.3.23 | EOL | |
| 4.2 | Nov 17, 2020 | — | May 16, 2022 | 4.2.19 | EOL | |
| 4.1 | Jun 23, 2020 | — | Dec 22, 2021 | 4.1.12 | EOL | |
| 4.0 | Jan 15, 2020 | — | Jul 14, 2021 | 4.0.12 | EOL |
CVEs affecting Neo4j 4.x (20)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 4.3 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 4.1 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 4.4 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 4.2 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 4.0 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 4.2 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 4.3 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 4.4 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 4.1 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 4.0 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 4.2 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 4.0 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 4.1 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 4.3 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 4.4 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 4.3 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 4.1 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 4.0 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 4.2 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.24% | — | 4.4 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
Neo4j 4.x is EOL — migrate to Neo4j 5.x
Neo4j 5.x is the next major release. Plan your upgrade before Neo4j 4.x stops receiving security patches.
Add a Neo4j 4 EOL badge to your README
Show your users which Neo4j version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/neo4j/4)Frequently asked questions
Is Neo4j 4 end of life?
Yes. All Neo4j 4.x releases have reached end of life and no longer receive security patches. There are 4 known CVEs affecting Neo4j 4.x, including 1 critical. Migrate to Neo4j 5.x as soon as possible.
What CVEs affect Neo4j 4?
There are 4 CVEs tracked for Neo4j 4.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.
What is the latest Neo4j 4 version?
The latest Neo4j 4.x patch release is 4.4.48, released on February 3, 2026. Always run the latest patch to benefit from all security fixes.
How to migrate from Neo4j 4 to Neo4j 5?
To migrate from Neo4j 4 to Neo4j 5: (1) review the official Neo4j 5 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Neo4j 4 in production?
No. Neo4j 4 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
