Neo4j 5.x — End of Life

Active Critical risk
EOL: Jun 6, 2028in 608d26 releases in this series6 CVEs

Neo4j 5.x is partially supported: only 5.26 still receives security fixes until Jun 6, 2028, in 608 days. The most recent release in this series is 5.26.31. 6 CVEs are tracked for this series, including 1 critical. 6 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Neo4j 2025. See Neo4j 2025 →

Neo4j 5.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
5.26LTSDec 6, 2024—Jun 6, 20285.26.31Active
5.25Oct 31, 2024—Dec 6, 20245.25.1EOL
5.24Sep 27, 2024—Oct 31, 20245.24.2EOL
5.23Aug 22, 2024—Sep 27, 20245.23.0EOL
5.22Jul 24, 2024—Aug 22, 20245.22.0EOL
5.21Jun 28, 2024—Jul 24, 20245.21.2EOL
5.20May 23, 2024—Jun 28, 20245.20.0EOL
5.19Apr 12, 2024—May 23, 20245.19.0EOL
5.18Mar 13, 2024—Apr 12, 20245.18.1EOL
5.17Feb 23, 2024—Mar 13, 20245.17.0EOL
5.16Jan 22, 2024—Feb 23, 20245.16.0EOL
5.15Dec 15, 2023—Jan 22, 20245.15.0EOL
5.14Nov 24, 2023—Dec 15, 20235.14.0EOL
5.13Oct 23, 2023—Nov 24, 20235.13.0EOL
5.12Sep 15, 2023—Oct 23, 20235.12.0EOL
5.11Aug 14, 2023—Sep 14, 20235.11.0EOL
5.10Jul 19, 2023—Aug 15, 20235.10.0EOL
5.9Jun 15, 2023—Jul 19, 20235.9.0EOL
5.8May 16, 2023—Jun 15, 20235.8.0EOL
5.7Apr 20, 2023—May 16, 20235.7.0EOL
5.6Mar 24, 2023—Apr 20, 20235.6.0EOL
5.5Feb 16, 2023—Mar 24, 20235.5.0EOL
5.4Jan 26, 2023—Feb 16, 20235.4.0EOL
5.3Dec 15, 2022—Jan 26, 20235.3.0EOL
5.2Nov 21, 2022—Dec 15, 20225.2.0EOL
5.1Oct 24, 2022—Nov 21, 20225.1.0EOL

CVEs affecting Neo4j 5.x (149)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-14587HIGH7.50.54%—5.20Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.2Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.9Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.24Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.1Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.16Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.21Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.6Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.18Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.8Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.7Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.15Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.4Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.19Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.22Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.14Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.3Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.13Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.26Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.5Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.10Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.12Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.25Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.11Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.17Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-14587HIGH7.50.54%—5.23Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask…Aug 5, 2026
CVE-2026-1524CRITICAL9.80.31%—5.13An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.26An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.1An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.15An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.11An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.24An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.16An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.9An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.2An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.20An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.23An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.25An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.12An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.10An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.5An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.3An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.14An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.22An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.19An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.7An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.8An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.18An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.6An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.17An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.4An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1524CRITICAL9.80.31%—5.21An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.19Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.13Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.15Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.5Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.20Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.22Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.4Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.14Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.16Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.3Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.24Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.17Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.25Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.2Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.6Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.1Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.9Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.12Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.11Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.18Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.26Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.21Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.8Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.10Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.23Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1471MEDIUM6.50.24%—5.7Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.10Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.20Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.23Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.25Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.17Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.12Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.13Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.11Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.5Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.26Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.3Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.21Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.14Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.15Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.22Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.4Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.19Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.7Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.8Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.1Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.18Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.24Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.6Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.16Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.9Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1497HIGH7.20.23%—5.2Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.…Mar 11, 2026
CVE-2026-1337MEDIUM5.40.24%—5.24Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.1Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.26Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.23Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.3Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.19Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.15Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.17Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.9Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.16Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.14Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.8Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.4Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.10Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.5Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.2Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.22Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.12Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.6Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.11Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.18Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.7Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.13Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.21Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.25Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2026-1337MEDIUM5.40.24%—5.20Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can…Feb 6, 2026
CVE-2024-34517MEDIUM6.50.62%—5.5The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.19The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.1The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.7The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.4The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.8The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.9The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.12The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.18The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.6The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.13The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.3The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.2The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.15The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.14The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.16The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.10The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.11The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024
CVE-2024-34517MEDIUM6.50.62%—5.17The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al…May 7, 2024

Neo4j 5.x will reach end of life — migrate to Neo4j 2025.x

Neo4j 2025.x is the next major release. Plan your upgrade before Neo4j 5.x stops receiving security patches.

See Neo4j 2025.x

Add a Neo4j 5 EOL badge to your README

Show your users which Neo4j version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Neo4j 5 EOL status
[![Neo4j 5 EOL status](https://eolcanary.com/badge/neo4j/5.svg)](https://eolcanary.com/explore/neo4j/5)

Frequently asked questions

Is Neo4j 5 end of life?

Partially. 25 of the 26 Neo4j 5.x releases have reached end of life. Still supported: 5.26 (until June 6, 2028 at the latest).

What CVEs affect Neo4j 5?

There are 6 CVEs tracked for Neo4j 5.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.

What is the latest Neo4j 5 version?

The latest Neo4j 5.x patch release is 5.26.31, released on September 21, 2026. Always run the latest patch to benefit from all security fixes.

How to migrate from Neo4j 5 to Neo4j 2025?

To migrate from Neo4j 5 to Neo4j 2025: (1) review the official Neo4j 2025 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Neo4j 5 in production?

Only on a supported release (5.26). Support for Neo4j 5.26 ends on June 6, 2028. Make sure you run the latest patch (5.26.31) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA