Search/CVE-2025-11602
CVE

CVE-2025-11602

Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses.

CVSS v3.1
EPSS
0.30%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
1 relationships
Timeline
disclosure → media coverage
Oct 31, 2025
Disclosure — published as a CVE record. · last revised by NVD Apr 15, 2026