ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary service degradation or unavailability.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arcadedata
Arcadedata arcadedb |
|
| Vendors & Products |
Arcadedata
Arcadedata arcadedb |
Tue, 18 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary service degradation or unavailability. | |
| Title | ArcadeDB before 26.8.1 Denial of Service via range() | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-18T11:19:49.914Z
Updated: 2026-08-18T14:16:15.855Z
Reserved: 2026-08-18T10:59:33.701Z
Link: CVE-2026-75841
Updated: 2026-08-18T14:15:43.816Z
Status : Deferred
Published: 2026-08-18T12:19:34.463
Modified: 2026-09-08T20:32:39.347
Link: CVE-2026-75841
No data.