Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/neo4j

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel. Because the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover the connection. The decoder re-reads the same first 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open. This can be triggered before authentication by any client that can reach the Bolt connector.

Join the discussion

CVE-2026-1622 is a medium severity vulnerability in Neo4j Enterprise and Community editions prior to versions 2026.01.3 and 5.26.21. It involves the insertion of sensitive information into query log files due to incomplete obfuscation of error messages when the 'obfuscate_literals' option is enabled. A user with legitimate access to local log files and the ability to run queries that trigger errors can infer unauthorized information from unredacted error details. The vulnerability does not require user interaction but does require local log file access and some privileges to run queries. The issue is fixed in the specified patched versions, and a new configuration option 'db.logs.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Package: pkg:github/neo4j
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses