---
id: CVE-2026-75841
title: >-
  ArcadeDB before 26.8.1 contains a denial of service vulnerability in the
  Cypher range() function that allows authenticated users to exhaust server heap
  memory
summary: >-
  ArcadeDB before 26.8.1 contains a denial of service vulnerability in the
  Cypher range() function that allows authenticated users to exhaust server heap
  memory. Attackers can submit oversized range() expressions with large bounds
  to trigg…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-770
published: '2026-08-18'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75841'
references:
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-xmjm-8q85-g778
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/arcadedb-before-denial-of-service-via-range
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-xmjm-8q85-g778
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00373
epssPercentile: 0.28476
ingestedAt: '2026-09-08T21:11:12.280Z'
---

## Overview

ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary service degradation or unavailability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
