GHSA-xr72-g735-4vwp · Severity: low · Ecosystem: maven — Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01. Proof of concept exploit: https://github.com/JoakimBulow/CVE-2026-1337
Conclusion & alert: CVE-2026-1337 is rated Exploit Available (50/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.04%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-07 | — | 0.04% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 1.1 | 4.0 | LOW |
|
— | — | 3b236295-4ccd-4a1f-a1c1-a72eecc8d7b6 |
| 5.4 | 3.1 | MEDIUM |
|
2.3 | 2.7 | [email protected] |
GHSA-xr72-g735-4vwp · Severity: low · Ecosystem: maven — Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2026-1337: 1 source package rows (neo4j); 3 state rows across 2 repos (3.23-community, edge-community); fixed 0, open 3. | https://security.alpinelinux.org/vuln/CVE-2026-1337 |
| URL | Tags |
|---|---|
| https://github.com/JoakimBulow/CVE-2026-1337 | Exploit Third Party Advisory |