Neo4j 4.x — End of Life
EOL Critical riskNeo4j 4.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 4.4LTS | Dec 2, 2021 | — | Nov 30, 2025 | 4.4.48 | EOL | |
| 4.3 | Jun 17, 2021 | — | Dec 16, 2022 | 4.3.23 | EOL | |
| 4.2 | Nov 17, 2020 | — | May 16, 2022 | 4.2.19 | EOL | |
| 4.1 | Jun 23, 2020 | — | Dec 22, 2021 | 4.1.12 | EOL | |
| 4.0 | Jan 15, 2020 | — | Jul 14, 2021 | 4.0.12 | EOL |
CVEs affecting Neo4j 4.x (20)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 4.3 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 4.1 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 4.4 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 4.2 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1524 | CRITICAL | 9.8 | 0.31% | — | 4.0 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 4.2 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 4.3 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 4.4 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 4.1 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.24% | — | 4.0 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 4.2 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 4.0 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 4.1 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 4.3 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1497 | HIGH | 7.2 | 0.23% | — | 4.4 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.… | Mar 11, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.20% | — | 4.3 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.20% | — | 4.1 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.20% | — | 4.0 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.20% | — | 4.2 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
| CVE-2026-1337 | MEDIUM | 5.4 | 0.20% | — | 4.4 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can… | Feb 6, 2026 |
Neo4j 4.x is EOL — migrate to Neo4j 5.x
Neo4j 5.x is the next major release. Plan your upgrade before Neo4j 4.x stops receiving security patches.
Frequently asked questions
Is Neo4j 4 end of life?
Yes. All Neo4j 4.x releases have reached end of life and no longer receive security patches. There are 20 known CVEs affecting Neo4j 4.x, including 5 critical. Migrate to Neo4j 5.x as soon as possible.
What CVEs affect Neo4j 4?
There are 20 CVEs tracked for Neo4j 4.x, including 5 critical severity issues. See the full list above with CVSS and EPSS scores.
What is the latest Neo4j 4 version?
The latest Neo4j 4.x patch release is 4.4.48, released on February 3, 2026. Always run the latest patch to benefit from all security fixes.
How to migrate from Neo4j 4 to Neo4j 5?
To migrate from Neo4j 4 to Neo4j 5: (1) review the official Neo4j 5 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Neo4j 4 in production?
No. Neo4j 4 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
