Vulnerability Description
ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary service degradation or unavailability.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-xmjm-8q85-g778
- https://www.vulncheck.com/advisories/arcadedb-before-denial-of-service-via-range
- https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-xmjm-8q85-g778
FAQ
What is CVE-2026-75841?
CVE-2026-75841 is a vulnerability with a CVSS score of 4.3 (MEDIUM). ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() e...
How severe is CVE-2026-75841?
CVE-2026-75841 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-75841?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.