parse-server
npm117 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting parse-serverpage 2 of 3
- CVE-2026-30941HIGHCVSS 7.5EG 7.5fixed in 9.5.2-alpha.1 or 8.6.14, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1, NoSQL injection vulnerability allows an unauthenticated attacker to inject MongoDB query operators v…
- CVE-2026-30946HIGHCVSS 7.5EG 7.5fixed in 8.6.15 or 9.5.2-alpha.2, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alpha.2 and 8.6.15, an unauthenticated attacker can exhaust Parse Server resources (CPU, memory, database connections) thro…
- CVE-2026-30947HIGHCVSS 7.5EG 7.5fixed in 9.5.2-alpha.3 or 8.6.16, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.3 and 8.6.16, class-level permissions (CLP) are not enforced for LiveQuery subscriptions. An unauthenticated or un…
- CVE-2026-30948MEDIUMCVSS 5.4EG 5.4fixed in 9.5.2-alpha.4 or 8.6.17, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.4 and 8.6.17, a stored cross-site scripting (XSS) vulnerability allows any authenticated user to upload an SVG fil…
- CVE-2026-30949HIGHCVSS 8.8EG 8.8fixed in 9.5.2-alpha.5 or 8.6.18, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keycloak authentication adapter does not validate the azp (authorized party) claim of Keycloak a…
- CVE-2026-30962MEDIUMCVSS 6.5EG 6.5fixed in 9.5.2-alpha.6 or 8.6.19, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.6 and 8.6.19, the validation for protected fields only checks top-level query keys. By wrapping a query constraint…
- CVE-2026-30965CRITICALCVSS 9.1EG 9.1fixed in 9.5.2-alpha.8 or 8.6.21, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker…
- CVE-2026-30966CRITICALCVSS 10.0EG 10.0fixed in 9.5.2-alpha.7 or 8.6.20, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field mappings such as role memberships, can be…
- CVE-2026-30967HIGHCVSS 8.8EG 8.8fixed in 9.5.2-alpha.9 or 8.6.22, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authentication adapter, when configured without the useridField option, only verifies th…
- CVE-2026-30972HIGHCVSS 7.5EG 7.5fixed in 9.5.2-alpha.10 or 8.6.23, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch re…
- CVE-2026-31800CRITICALCVSS 9.1EG 9.1fixed in 9.5.2-alpha.12 or 8.6.25, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.12 and 8.6.25, the _GraphQLConfig and _Audience internal classes can be read, modified, and deleted via the generi…
- CVE-2026-31828HIGHCVSS 8.8EG 8.8fixed in 9.5.2-alpha.13 or 8.6.26, by version range2026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) …
- CVE-2026-31840CRITICALCVSS 9.8EG 9.8fixed in 9.6.0-alpha.2 or 8.6.28, by version range2026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject…
- CVE-2026-31856CRITICALCVSS 9.8EG 9.8fixed in 9.6.0-alpha.3 or 8.6.29, by version range2026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields usi…
- CVE-2026-31868MEDIUMCVSS 6.1EG 6.1fixed in 9.6.0-alpha.4 or 8.6.30, by version range2026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.4 and 8.6.30, an attacker can upload a file with a file extension or content type that is not blocked by the defau…
- CVE-2026-31871CRITICALCVSS 9.8EG 9.8fixed in 9.6.0-alpha.5 or 8.6.31, by version range2026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment ope…
- CVE-2026-31872HIGHCVSS 7.5EG 7.5fixed in 9.6.0-alpha.6 or 8.6.32, by version range2026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE c…
- CVE-2026-31875MEDIUMCVSS 5.9EG 5.9fixed in 9.6.0-alpha.7 or 8.6.33, by version range2026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled for a user account, Parse Server generate…
- CVE-2026-31901MEDIUMCVSS 5.3EG 5.3fixed in 9.6.0-alpha.8 or 8.6.34, by version range2026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endpoint (/verificationEmailRequest) returns distinct error responses dependi…
- CVE-2026-32098HIGHCVSS 7.5EG 7.5fixed in 9.6.0-alpha.9 or 8.6.35, by version range2026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.9 and 8.6.35, an attacker can exploit LiveQuery subscriptions to infer the values of protected fields without dire…
- CVE-2026-32234MEDIUMCVSS 4.7EG 4.7fixed in 9.6.0-alpha.10 or 8.6.36, by version range2026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.10 and 8.6.36, an attacker with access to the master key can inject malicious SQL via crafted field names used in …
- CVE-2026-32242HIGHCVSS 7.4EG 7.4fixed in 9.6.0-alpha.11 or 8.6.37, by version range2026-03-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly ac…
- CVE-2026-32248CRITICALCVSS 9.8EG 9.8fixed in 9.6.0-alpha.12 or 8.6.38, by version range2026-03-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication …
- CVE-2026-32269MEDIUMCVSS 6.5EG 6.5fixed in 9.6.0-alpha.13 or 8.6.39, by version range2026-03-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication adapter does not correctly validate app IDs when appidField and appIds ar…
- CVE-2026-32594HIGHCVSS 7.3EG 7.3fixed in 9.6.0-alpha.14 or 8.6.40, by version range2026-03-16
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middlew…
- CVE-2026-32728HIGHCVSS 7.6EG 7.6fixed in 9.6.0-alpha.15 or 8.6.41, by version range2026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attacker who is allowed to upload files can bypass the file extension filter by appending a MIME…
- CVE-2026-32742MEDIUMCVSS 4.3EG 4.3fixed in 9.6.0-alpha.17 or 8.6.42, by version range2026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.17 and 8.6.42, an authenticated user can overwrite server-generated session fields (`sessionToken`, `expiresAt`, `…
- CVE-2026-32770HIGHCVSS 7.5EG 7.5fixed in 9.6.0-alpha.19 or 8.6.43, by version range2026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.19 and 8.6.43, a remote attacker can crash the Parse Server by subscribing to a LiveQuery with an invalid regular …
- CVE-2026-32878HIGHCVSS 7.5EG 7.5fixed in 9.6.0-alpha.20 or 8.6.44, by version range2026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.20 and 8.6.44, an attacker can bypass the default request keyword denylist protection and the class-level permissi…
- CVE-2026-32886HIGHCVSS 7.5EG 7.5fixed in 9.6.0-alpha.24 or 8.6.47, by version range2026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.24 and 8.6.47, remote clients can crash the Parse Server process by calling a cloud function endpoint with a craft…
- CVE-2026-32943LOWCVSS 3.1EG 3.1fixed in 9.6.0-alpha.28 or 8.6.48, by version range2026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.28 and 8.6.48, the password reset mechanism does not enforce single-use guarantees for reset tokens. When a user r…
- CVE-2026-32944HIGHCVSS 7.5EG 7.5fixed in 9.6.0-alpha.21 or 8.6.45, by version range2026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.21 and 8.6.45, an unauthenticated attacker can crash the Parse Server process by sending a single request with dee…
- CVE-2026-33042MEDIUMCVSS 5.3EG 5.3fixed in 9.6.0-alpha.29 or 8.6.49, by version range2026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.29 and 8.6.49, a user can sign up without providing credentials by sending an empty `authData` object, bypassing t…
- CVE-2026-33163MEDIUMCVSS 6.5EG 6.5fixed in 9.6.0-alpha.35 or 8.6.50, by version range2026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the LiveQuery server le…
- CVE-2026-33323MEDIUMCVSS 5.3EG 5.3fixed in 9.6.0-alpha.40 or 8.6.51, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for resending email verification links return d…
- CVE-2026-33409CRITICALCVSS 9.1EG 9.1fixed in 9.6.0-alpha.41 or 8.6.52, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an attacker to log in as any user who has li…
- CVE-2026-33421MEDIUMCVSS 6.5EG 6.5fixed in 9.6.0-alpha.42 or 8.6.53, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.53 and 9.6.0-alpha.42, Parse Server's LiveQuery WebSocket interface does not enforce Class-Level Permission (CLP)…
- CVE-2026-33429MEDIUMCVSS 5.3EG 5.3fixed in 9.6.0-alpha.43 or 8.6.54, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.54 and 9.6.0-alpha.43, an attacker can subscribe to LiveQuery with a watch parameter targeting a protected field.…
- CVE-2026-33498HIGHCVSS 7.5EG 7.5fixed in 9.6.0-alpha.44 or 8.6.55, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.55 and 9.6.0-alpha.44, an attacker can send an unauthenticated HTTP request with a deeply nested query containing…
- CVE-2026-33508HIGHCVSS 7.5EG 7.5fixed in 9.6.0-alpha.45 or 8.6.56, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.56 and 9.6.0-alpha.45, Parse Server's LiveQuery component does not enforce the requestComplexity.queryDepth confi…
- CVE-2026-33527MEDIUMCVSS 4.3EG 4.3fixed in 9.6.0-alpha.48 or 8.6.57, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.57 and 9.6.0-alpha.48, an authenticated user can overwrite server-generated session fields such as expiresAt and …
- CVE-2026-33538HIGHCVSS 7.5EG 7.5fixed in 9.6.0-alpha.52 or 8.6.58, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.58 and 9.6.0-alpha.52, an unauthenticated attacker can cause denial of service by sending authentication requests…
- CVE-2026-33539HIGHCVSS 7.2EG 7.2fixed in 9.6.0-alpha.53 or 8.6.59, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.59 and 9.6.0-alpha.53, an attacker with master key access can execute arbitrary SQL statements on the PostgreSQL …
- CVE-2026-33624LOWCVSS 2.7EG 2.7fixed in 9.6.0-alpha.54 or 8.6.60, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54, an attacker who obtains a user's password and a single MFA recovery code can reuse that re…
- CVE-2026-33627MEDIUMCVSS 6.5EG 6.5fixed in 9.6.0-alpha.55 or 8.6.61, by version range2026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, an authenticated user calling GET /users/me receives unsanitized auth data, including sens…
- CVE-2026-34215MEDIUMCVSS 6.5EG 6.5fixed in 9.7.0-alpha.7 or 8.6.63, by version range2026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data, including MFA TOTP se…
- CVE-2026-34224MEDIUMCVSS 4.4EG 4.4fixed in 9.7.0-alpha.8 or 8.6.64, by version range2026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a single MFA recovery c…
- CVE-2026-34363MEDIUMCVSS 5.3EG 5.3fixed in 9.7.0-alpha.9 or 8.6.65, by version range2026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers process…
- CVE-2026-34373HIGHCVSS 8.8EG 8.8fixed in 9.7.0-alpha.10 or 8.6.66, by version range2026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditionall…
- CVE-2026-34532CRITICALCVSS 9.1EG 9.1fixed in 9.7.0-alpha.11 or 8.6.67, by version range2026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.co…
Check whether parse-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for parse-server CVEs against the assets you own.
Book a Demo →