{"id":"CVE-2025-11602","summary":"Untargeted information leak in Bolt protocol handshake","details":"Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses.","modified":"2026-08-12T15:16:16.250199Z","published":"2025-10-31T10:20:17.254Z","database_specific":{"cna_assigner":"Neo4j","cwe_ids":["CWE-226"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11602.json"},"references":[{"type":"WEB","url":"https://mvnrepository.com/artifact/org.neo4j/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11602.json"},{"type":"ADVISORY","url":"https://neo4j.com/security/cve-2025-11602"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11602"},{"type":"PACKAGE","url":"https://github.com/neo4j/neo4j"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/neo4j/neo4j","events":[{"introduced":"c68156edf24164435ab1ac257ec633134c2887f7"},{"fixed":"679feffbfb7a9189aba360ea98eef7fc3371e275"},{"introduced":"0"},{"fixed":"503a3228c34cb48495838fb7866b46d1a7a49640"}],"database_specific":{"extracted_events":[{"introduced":"5.26.0"},{"fixed":"5.26.15"},{"introduced":"2025.1.0"},{"fixed":"2025.10.1"}],"source":"AFFECTED_FIELD"}}],"versions":["5.26.14","1.0.0","5.2.0","5.1.0","5.0.0","4.4.0-alpha01","4.1.0-alpha01","4.0.0-beta03mr03","4.0.0-beta02","4.0.0-beta01","4.0.0-alpha10","4.0.0-alpha09mr02","4.0.0-alpha08","4.0.0-alpha07mr01","4.0.0-alpha06","4.0.0-alpha05","4.0.0-alpha04","4.0.0-alpha03","4.0.0-alpha02","4.0.0-alpha01","3.4.0-rc01","3.4.0-beta02","3.4.0-beta01","3.4.0-alpha10","3.4.0-alpha09","3.4.0-alpha08","3.4.0-alpha07","3.4.0-alpha06","3.4.0-alpha05","3.4.0-alpha04","3.4.0-alpha03","3.4.0-alpha02","3.4.0-alpha01","3.3.0-beta01","3.3.0-alpha07","3.3.0-alpha06","3.3.0-alpha05","3.3.0-alpha04","3.3.0-alpha03","3.3.0-alpha02","3.3.0-alpha01","3.2.0-rc1","3.2.0-alpha08","3.2.0-alpha07","3.2.0-alpha06","3.2.0-alpha05","3.2.0-alpha04","3.2.0-alpha03","3.2.0-alpha02","3.2.0-alpha01","3.1.0-M13-beta3","3.1.0-M12-beta2","3.1.0-BETA1","3.1.0-M10","3.1.0-M09","3.1.0-M08","3.1.0-M07","3.1.0-M06","3.1.0-M05","3.1.0-M04","3.1.0-M03","3.1.0-M02","3.1.0-M01","3.0.0-M05","3.0.0-M04","3.0.0-M03","3.0.0-M02","3.0.0-M01","2.3.0-M02","2.3.0-M01","2.2.0-RC01","2.2.0-M03","2.2.0-M01","2.0.1","1.9","1.9.M02"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11602.json","vanir_signatures_modified":"2026-08-12T15:16:16Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/neo4j/neo4j/commit/503a3228c34cb48495838fb7866b46d1a7a49640","target":{"file":"community/import-util/src/main/java/org/neo4j/internal/batchimport/input/csv/CsvInputParser.java"},"deprecated":false,"digest":{"line_hashes":["165405073164466355856484131197656697372","315350690192413017077834739152247313598","167053678267040645784882238546715245589"],"threshold":0.9},"id":"CVE-2025-11602-137a4995"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/neo4j/neo4j/commit/679feffbfb7a9189aba360ea98eef7fc3371e275","target":{"file":"community/values/src/main/java/org/neo4j/values/virtual/VirtualValues.java"},"deprecated":false,"digest":{"line_hashes":["58970849500403829944582057193592439025","24002357499004360269436090087374852192","44482330476924172396131051331659487300","175190630216774108156272858353749505656","107624872759720048369611582148395048731","236058155626836023837954493901153701497","301749628178757643742810909157554005109"],"threshold":0.9},"id":"CVE-2025-11602-2b3b03a5"},{"id":"CVE-2025-11602-35a63b39","signature_type":"Line","signature_version":"v1","source":"https://github.com/neo4j/neo4j/commit/503a3228c34cb48495838fb7866b46d1a7a49640","target":{"file":"community/import-api/src/main/java/org/neo4j/batchimport/api/input/InputEntityVisitor.java"},"deprecated":false,"digest":{"line_hashes":["210712790669227534505264526137620560443","42263896817157907145994691986323464813","150701581007966175986352092738070283707","144431992881239007110496729211895545491","54549510919079472104385061930284380546","32376807314179020864871475204210999130","192649166444599404237109328963537243021"],"threshold":0.9}},{"deprecated":false,"digest":{"line_hashes":["240104574855275578799273254647917767956","39823324111006501890027243829440459042","304446613010666323527171181660812558113"],"threshold":0.9},"id":"CVE-2025-11602-924294f2","signature_type":"Line","signature_version":"v1","source":"https://github.com/neo4j/neo4j/commit/503a3228c34cb48495838fb7866b46d1a7a49640","target":{"file":"community/import-util/src/main/java/org/neo4j/internal/batchimport/input/BatchedInputEntityVisitor.java"}},{"signature_version":"v1","source":"https://github.com/neo4j/neo4j/commit/679feffbfb7a9189aba360ea98eef7fc3371e275","target":{"file":"community/values/src/main/java/org/neo4j/values/virtual/ListValueBuilder.java"},"deprecated":false,"digest":{"line_hashes":["97787134369167755272516415826081286361","198474545482414191058596680429451161343","5302631034999650072290505434734215283","275034141696303982812678394383047153976","339246081830576450792803699348324380478","226354553859003503567344045700768991275","182563418118328906776764998907319956850"],"threshold":0.9},"id":"CVE-2025-11602-a9b73b62","signature_type":"Line"},{"digest":{"function_hash":"207892346322277362774774240986762922004","length":3363},"id":"CVE-2025-11602-c00eae50","signature_type":"Function","signature_version":"v1","source":"https://github.com/neo4j/neo4j/commit/503a3228c34cb48495838fb7866b46d1a7a49640","target":{"file":"community/import-util/src/main/java/org/neo4j/internal/batchimport/input/csv/CsvInputParser.java","function":"next"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/V:D/U:Clear"}]}