Denial of Service Vulnerability in ArcadeDB by ArcadeData
CVE-2026-75841
5.3MEDIUM
What is CVE-2026-75841?
ArcadeDB versions prior to 26.8.1 contain a denial of service vulnerability in the Cypher range() function. This flaw allows authenticated users to craft oversized range expressions with large bounds, leading to heap memory exhaustion. When exploited, this causes an OutOfMemoryError, resulting in temporary degradation or unavailability of the affected service.
Affected Version(s)
arcadedb 0 < 26.8.1
arcadedb 26.8.1
