Release Date: 25 August 2026

Release (1.15.5)

Patch release

  • All releases from Neo4j Ops Manager 1.15.0 and later require Neo4j persistence to be version 5.26 LTS or greater. 
  • Monitoring instances with versions of 4.4 LTS and greater is still supported, although 4.4 LTS is out of support with Neo4j.
See Version Compatibility Docs

Changes

  • This release includes the latest versions of base docker images, along with fixes for a number of CVEs.

Fixes

  • This release resolves the following high and critical priority CVEs in dependencies:
    • CVE-2026-67213
    • CVE-2026-67214
    • CVE-2026-22030
    • CVE-2026-69192
    • CVE-2026-13697
    • CVE-2026-73646
    • CVE-2026-55685
    • CVE-2026-59880
    • CVE-2026-59879
    • CVE-2026-13311
    • CVE-2026-59869
    • CVE-2026-59880

Internal

  • immutable to 5.1.9
  • shell-quote to 1.10.0
  • ip-address to 10.4.0
  • undici to 7.29.0
  • dompurify to 3.4.13
  • nanoid to 3.3.18
  • mermaid to 11.16.1
  • postcss to 8.5.23
  • @auth0/auth0-react to 2.23.0
  • @azure/msal-browser to 5.18.0
  • @azure/msal-react to 5.5.5
  • @neo4j-ndl/base to 4.17.2
  • @neo4j-ndl/react to 4.18.2
  • @segment/analytics-next to 1.84.1
  • @table-nav/core to 0.0.10
  • @table-nav/react to 0.0.10
  • auth0-js to 10.2.1
  • immer to 11.1.16
  • react to 19.2.8
  • @types/react to 19.2.18
  • react-dom to 19.2.8
  • @types/react-dom to 19.2.4
  • react-hook-form to 7.84.0
  • react-router-dom to 7.18.2
  • semver to 7.8.5
  • @types/semver to 7.8.0
  • @axe-core/playwright to 4.12.1
  • @graphql-codegen/cli to 7.2.0
  • @graphql-codegen/introspection to 6.1.0
  • @graphql-codegen/typescript to 6.1.0
  • @graphql-codegen/typescript-operations to 6.1.5
  • @graphql-tools/mock to 9.1.12
  • @playwright/test to 1.62.1
  • @testing-library/user-event to 14.6.3
  • @types/lodash to 4.17.25
  • @typescript-eslint/eslint-plugin to 8.66.0
  • @typescript-eslint/parser to 8.66.0
  • @vitejs/plugin-legacy to 8.2.3
  • @vitejs/plugin-react to 6.0.5
  • pm2 to 7.0.3
  • postcss to 8.5.26
  • prettier to 3.9.6
  • terser to 5.49.2
  • type-coverage to 2.30.1
  • type-fest to 5.8.0
  • vite to 8.2.1
  • vitest to 4.1.10
  • org.bouncycastle:bcpkix-jdk18on to 1.85
  • google.golang.org/grpc to 1.83.0
  • com.networknt:json-schema-validator to 3.0.6
  • neo4j-migrations-spring-boot-starter to 4.1.2
  • pmd.version to 7.26.0
  • org.apache.maven.plugins:maven-jar-plugin to 3.5.1
  • google.golang.org/protobuf to 1.36.12
  • grpc.version to 1.83.1
  • org.jsoup:jsoup to 1.23.1
  • golang.org/x/crypto to 0.55.0
  • org.apache.tomcat.embed:tomcat-embed-core to 11.0.25
  • net.bytebuddy:byte-buddy to 1.18.12

Known issues

pkg:golang/[email protected]
  • Vulnerabilty scans might report the NOM docker image with CRITICAL CVE-2026-39821 HIGH CVE-2026-56862 HIGH CVE-2026-56859 HIGH CVE-2026-56853 HIGH CVE-2026-46600 HIGH CVE-2026-33818 MEDIUM CVE-2026-56858 MEDIUM CVE-2026-56860
Due to the base image, our docker image does contain this lib but the go environment it belongs to is not used by Neo4j Ops Manager. They can safely be ignored.

tools.jackson.core/jackson-databind 3.1.4
  • Vulnerabilty scans might report MEDIUM CVE-2026-59889
Neo4j Ops Manager does not use the affected code and thus is not affected by this.