Release Date: 22 September 2026

Bug fixes

Cypher

  • plain text query log now escapes potentially dangerous unicode characters to avoid log injection.  Fixes CVE-2026-1337 and GHSA-xr72-g735-4vwp.

Security

  • Bump jackson dependency to 2.22.2 to fix CVE-2026-19032, CVE-2026-68497, CVE-2026-83557.
Please refer to the changelog for full details of the changes.

Bundled Packages:

  • labs/apoc-5.26.31.
  • lib/neo4j-browser-2026.09.21+0
  • products/bloom-plugin-5.x-2.36.0
  • products/neo4j-genai-plugin-5.26.20
  • products/neo4j-graph-data-science-2.13.13
  • products/neo4j-ops-manager-agent-1.15.5
  • product/fleetManagement-1.2.0