What is CVE-2026-75841?
CVE-2026-75841 is a denial of service vulnerability in ArcadeDB before version 26.8.1, triggered via the Cypher range() function. Authenticated attackers can exhaust server heap memory by submitting oversized range() expressions with large bounds, leading to OutOfMemoryError and temporary service degradation. Users should upgrade to version 26.8.1 or later.
Azərbaycanca: CVE-2026-75841, ArcadeDB-nin 26.8.1 versiyasından əvvəlki versiyalarında Cypher range() funksiyasında autentifikasiya olunmuş istifadəçilərə server heap yaddaşını tükəndirməyə imkan verən denial of service (DoS) zəifliyidir. Bu, oversized range() ifadələri ilə OutOfMemoryError yaradaraq müvəqqəti xidmət deqradasiyasına səbəb olur. İstifadəçilərə 26.8.1 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What type of attack can be performed exploiting CVE-2026-75841?
This vulnerability leads to a denial of service (DoS) attack. Authenticated attackers can exhaust the server heap memory via the range() function in the Cypher query language, causing an OutOfMemoryError and resulting in temporary service degradation.
What is recommended for users to mitigate CVE-2026-75841?
Users are recommended to upgrade ArcadeDB to version 26.8.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.