Neo4j Community and Enterprise edition versions 5.0 to 5.26.29 and 2025.1.0 to 2026.07 are vulnerable to a potential Denial of Service in Bolt protocol handshake.
The vulnerability allows attacker to keep the channel open by sending a crafted package. We recommend upgrading to 5.26.29 or 2026.07 or above, where the issue is fixed.
The issue is not applicable to AuraDB – Neo4j Fully Managed Cloud Service