from 0, < 3.4.19
MEDIUM6.5CVE-2024-34517Neo4j Cypher component mishandles IMMUTABLE privileges >= 5.0.0, < 5.20.0
—CVE-2026-1524Auth misconfiguration when multiple providers enabled from 0, < 5.26.22, >= 2025.1.0, < 2026.2.0
—Caching of authentication context
from 0, < 5.26.22, >= 2025.1.0, < 2026.1.4
—Incorrect privilege assignment in composite databases
from 0, < 5.26.22, >= 2025.1.0, < 2026.2.0
—Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log
from 0, < 2026.1.0