Neo4j

Neo4j 5.26 (LTS)

Neo4j 5.26 (LTS)

Third-party support for the Neo4j 5.26 (LTS): 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.

EOSL Date: Jun 6, 2028
Issue Management

24/7 engineers own your Neo4j 5.26 (LTS) incidents end to end.

Vulnerability Remediation

Mitigation and patch-around guidance when the vendor no longer ships fixes.

Compliance Maintenance

Controls evidence and documentation that keep auditors satisfied.

Specifications

product
neo4j
release
5.26
product Label
Neo4j
release Label
5.26 (LTS)
codename
lts
true
latest Version
5.26.30
release Date
2024-12-06
maintained
true
source Url
https://endoflife.date/neo4j

Lifecycle Dates

End of Service Life
Jun 6, 2028
Last OEM Support
Jun 6, 2028

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how third-party support compares to the vendor contract for Neo4j 5.26 (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.

FeatureOEM Support3rd Party Support
Post-EOSL Support
Break/Fix Support
Until EOSL
24/7 Monitoring
Vulnerability Scanning & Remediation
Managed Operations
Procedure & Configuration Review
Compliance & Audit Documentation
Limited
Discounted Migration to Other Platforms

Why Choose 3rd Party Support for Neo4j 5.26 (LTS)?

Vulnerability Remediation

Scanning, mitigation and patch-around guidance for Neo4j 5.26 (LTS) when the vendor no longer ships fixes.

Compliance Maintenance

Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.

24/7 Expert Support

Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.

Neo4j 5.26 (LTS) Support: Frequently Asked Questions

Is the Neo4j 5.26 (LTS) still supported?

Yes. The Neo4j 5.26 (LTS) is currently supported by Neo4j, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.

When is the Neo4j 5.26 (LTS) end of service life (EOSL) date?

Neo4j lists the end of service life for the Neo4j 5.26 (LTS) as Jun 6, 2028.

Can I keep using the Neo4j 5.26 (LTS) after its EOSL date?

Yes. EOSL means Neo4j stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.

How much does third-party support for the Neo4j 5.26 (LTS) cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting Neo4j 5.26 (LTS)

5 published CVEs affect the Neo4j 5.26 (LTS). Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.

CVESeverityCVSSPublishedSummary
CVE-2026-14587MEDIUM5.5Aug 5, 2026Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel. Because the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover
CVE-2026-1524LOW2.1Mar 11, 2026An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one or more of them to be an authorization provider AND configures one or more of them to be authentication-only, then those that are authentication-only will also provide authorization. This edgecase becomes a security problem only if the authentication-only provider
CVE-2026-1471LOW2.1Mar 11, 2026Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the context of the first user who authenticated after restart. The issue is limited to certain non-default configurations of SSO (UserInfo endpoint).  We recommend upgrading to versions 2026.01.4 (or 5.26.22) where the issue is fixed.
CVE-2026-1497LOW2.0Mar 11, 2026Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:  an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently grant access to any local database or remote alias called "name". If such database or alias doesn't exist when the command is run, the privileges will apply if it's created in the future.
CVE-2026-1337LOW1.1Feb 6, 2026Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01. Proof of concept exploit:  https://github.com/JoakimBulow/CVE-2026-1337
Get Third Party Support

Related Neo4j Products

All Neo4j products →
Neo4j 5.26 (LTS)
Save 40-70% vs OEM
Get Third Party Support