PT-2026-76941 · Arcadedb · Arcadedb
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.8.1
Description
Authenticated users can cause a denial of service by exhausting server heap memory. This occurs when oversized expressions are submitted to the Cypher
range() function with large bounds, triggering an OutOfMemoryError, which leads to temporary service degradation or unavailability.Recommendations
Update to version 26.8.1 or later.
As a temporary mitigation, restrict the use of the
range() function for authenticated users.Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb