CVE-2025-11602
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-31
Last updated on: 2025-11-04
Assigner: Neo4j
Description
Description
Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| neo4j | neo4j | 5.26.14 |
| neo4j | neo4j | 2025.10.0 |
| neo4j | neo4j | 2025.1.0 |
| neo4j | neo4j | 5.26.0 |
| neo4j | neo4j | 2025.10.1 |
| neo4j | neo4j | 5.26.15 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-226 | The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities. |