Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-14587

CVE-2026-14587: Neo4j Bolt Auth Bypass Vulnerability

CVE-2026-14587 is an authentication bypass flaw in Neo4j's Bolt connector that allows unauthenticated clients to exploit handshake processing. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-14587 Overview

CVE-2026-14587 affects the Neo4j Bolt modern handshake decoder. The decoder treats an overlong capability bit mask identically to a truncated bit mask. An unauthenticated client can send a selected protocol version followed by 32 continuation bytes in the capability mask. The decoder resets the reader index and waits for additional bytes instead of rejecting the message and closing the channel.

The same unread bytes remain at the front of the decoder buffer. Appending a terminating byte later does not recover the connection. The decoder re-reads the same 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open. Any client able to reach the Bolt connector can trigger the condition before authentication.

Critical Impact

Unauthenticated attackers with network access to the Bolt connector can hold connections open indefinitely, consuming server-side resources and creating conditions for denial of service against Neo4j deployments.

Affected Products

  • Neo4j graph database implementations exposing the Bolt connector
  • Neo4j Bolt modern handshake protocol decoder
  • Any deployment reachable on the Bolt network port prior to authentication

Discovery Timeline

  • 2026-08-05 - CVE-2026-14587 published to NVD
  • 2026-08-05 - Last updated in NVD database

Technical Details for CVE-2026-14587

Vulnerability Analysis

The flaw resides in the Bolt modern handshake decoder logic that parses capability bit masks. Bolt is Neo4j's binary application protocol used by drivers to communicate with the database. During the handshake, the client sends a selected protocol version and a variable-length capability bit mask. The mask uses continuation bytes to signal additional length.

The decoder handles two abnormal conditions using the same code path. A truncated mask, where the client has not yet transmitted enough bytes, correctly instructs the decoder to wait for more data. However, an overlong mask containing 32 continuation bytes without a terminator receives identical treatment. Rather than treating an oversized mask as a protocol violation, the decoder resets its reader index and re-parses the same buffer on the next read.

This behavior maps to [CWE-130] Improper Handling of Length Parameter Inconsistency. The channel remains open, consuming file descriptors, memory, and connection slots. Because the trigger occurs pre-authentication, no credentials are required.

Root Cause

The root cause is decoder state logic that fails to distinguish between an incomplete frame and a malformed oversized frame. Both conditions cause the decoder to return without producing a handshake-finalization message. The reader index reset ensures the malformed bytes persist across subsequent reads, preventing self-recovery.

Attack Vector

An attacker sends a crafted Bolt handshake containing a valid protocol version selector followed by 32 capability mask continuation bytes with no terminating byte. The connection remains open in a permanent waiting state. Repeating the pattern across many connections exhausts server capacity. The vulnerability requires only network reachability to the Bolt port and no authentication.

Refer to the Neo4j CVE-2026-14587 Advisory for vendor technical details.

Detection Methods for CVE-2026-14587

Indicators of Compromise

  • Unusual accumulation of half-open Bolt connections that remain in a pre-authentication state for extended periods
  • Spikes in Bolt connector file descriptor usage without corresponding successful authentication events
  • Client source addresses opening multiple connections that never complete the handshake-finalization step

Detection Strategies

  • Instrument the Bolt connector to log handshake bytes received per connection and flag sessions that exceed expected capability mask sizes
  • Correlate network flow data with Neo4j authentication logs to identify connections that transmit data but never authenticate
  • Alert on sustained increases in concurrent Bolt connections that outpace successful query execution counts

Monitoring Recommendations

  • Track Neo4j server metrics for open connection count, memory consumption, and file descriptor usage against baseline
  • Monitor perimeter and internal firewall logs for unexpected sources connecting to the Bolt port (default 7687)
  • Enable verbose Bolt handshake logging in test environments to establish signatures for the malformed capability mask pattern

How to Mitigate CVE-2026-14587

Immediate Actions Required

  • Consult the Neo4j CVE-2026-14587 Advisory and apply the fixed release identified by the vendor
  • Restrict network access to the Bolt connector so only trusted application tiers can reach port 7687
  • Review current connection limits and configure conservative maximums to bound resource consumption during exploitation attempts

Patch Information

Neo4j has published an advisory at neo4j.com/security/CVE-2026-14587. Administrators should upgrade to the fixed version specified by the vendor. No public exploit code is currently referenced in the NVD entry.

Workarounds

  • Place the Bolt connector behind a network access control list that permits only known driver source addresses
  • Enforce connection rate limits and idle timeouts at a reverse proxy or load balancer in front of Neo4j
  • Disable the Bolt connector where drivers connect exclusively through HTTP if operationally feasible
bash
# Example: restrict Bolt connector binding and enforce timeouts in neo4j.conf
server.bolt.listen_address=127.0.0.1:7687
server.bolt.thread_pool_min_size=5
server.bolt.thread_pool_max_size=200
server.bolt.thread_pool_keep_alive=5m

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.