3.5 - Security fixes


Security fixes provided in 3.5.0-funcrel

CAST service CVE Severity Description/Package Affected CAST release
ai-service CVE-2025-65106 HIGH langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates 3.4.5-funcrel
analysis-node CVE-2025-59375 HIGH expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing 3.4.5_core8.4.7
analysis-node CVE-2025-8176 HIGH libtiff: LibTIFF Use-After-Free Vulnerability 3.4.5_core8.4.7
neo4j CVE-2023-43000 HIGH webkitgtk: Processing maliciously crafted web content may lead to memory corruption 3.4.5-funcrel
neo4j CVE-2025-11021 HIGH libsoup: Out-of-Bounds Read in Cookie Date Handling of libsoup HTTP Library 3.4.5-funcrel
neo4j CVE-2025-13502 HIGH webkit: WebKitGTK / WPE WebKit: Out-of-bounds read and integer underflow vulnerability leading to DoS 3.4.5-funcrel
neo4j CVE-2025-43272 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash 3.4.5-funcrel
neo4j CVE-2025-43342 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash 3.4.5-funcrel
neo4j CVE-2025-43343 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash 3.4.5-funcrel
neo4j CVE-2025-43368 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash 3.4.5-funcrel
neo4j CVE-2025-43419 HIGH webkitgtk: Processing maliciously crafted web content may lead to memory corruption 3.4.5-funcrel
neo4j CVE-2025-43421 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash 3.4.5-funcrel
neo4j CVE-2025-43425 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash 3.4.5-funcrel
neo4j CVE-2025-43427 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash 3.4.5-funcrel
neo4j CVE-2025-43429 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash 3.4.5-funcrel
neo4j CVE-2025-43430 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash 3.4.5-funcrel
neo4j CVE-2025-43431 HIGH webkitgtk: Processing maliciously crafted web content may lead to memory corruption 3.4.5-funcrel
neo4j CVE-2025-43432 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash 3.4.5-funcrel
neo4j CVE-2025-43434 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash 3.4.5-funcrel
neo4j CVE-2025-43440 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash 3.4.5-funcrel
neo4j CVE-2025-43443 HIGH webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash 3.4.5-funcrel
neo4j CVE-2025-59375 HIGH expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing 3.4.5-funcrel
neo4j CVE-2025-6965 HIGH sqlite: Integer Truncation in SQLite 3.4.5-funcrel
neo4j CVE-2025-8176 HIGH libtiff: LibTIFF Use-After-Free Vulnerability 3.4.5-funcrel
neo4j CVE-2025-9900 HIGH libtiff: Libtiff Write-What-Where 3.4.5-funcrel
viewer CVE-2025-64720 HIGH libpng: LIBPNG buffer overflow 3.4.5-funcrel
viewer CVE-2025-65018 HIGH libpng: LIBPNG heap buffer overflow 3.4.5-funcrel