What is CVE-2026-14587?
CVE-2026-14587 is a vulnerability in Neo4j's Bolt modern handshake decoder where an overlong capability bit mask from an unauthenticated client resets the reader index, causing it to wait for more data. This can lead to a denial-of-service (DoS) condition. Affected Neo4j users should apply the vendor-provided security update.
Azərbaycanca: CVE-2026-14587, Neo4j-in Bolt müasir "handshake" dekoderində olan zəiflikdir. Doğrulanmamış müştəri tərəfindən göndərilən xüsusi hazırlanmış uzun "capability bit mask"-i deşifrə edərkən oxucu indeksini sıfırlayır və daha çox məlumat gözləməyə davam edir, bu da xidmətin dayanmasına (DoS) səbəb ola bilər. Neo4j istifadəçiləri təchizatçı tərəfindən təqdim edilən təhlükəsizlik yeniləməsini tətbiq etməlidir.
FAQ2
Which Neo4j component is affected by CVE-2026-14587?
Neo4j's Bolt modern handshake decoder.
How can users protect themselves from CVE-2026-14587?
By applying the vendor-provided security update.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.