parse-server
npm117 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting parse-serverpage 2 of 3
- CVE-2026-30941HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.142026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1, NoSQL injection vulnerability allows an unauthenticated attacker to inject MongoDB query operators v…
- CVE-2026-30946HIGHCVSS 7.5EG 7.5✓ Fixed in 9.5.2-alpha.22026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alpha.2 and 8.6.15, an unauthenticated attacker can exhaust Parse Server resources (CPU, memory, database connections) thro…
- CVE-2026-30947HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.162026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.3 and 8.6.16, class-level permissions (CLP) are not enforced for LiveQuery subscriptions. An unauthenticated or un…
- CVE-2026-30948MEDIUMCVSS 5.4EG 5.4✓ Fixed in 8.6.172026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.4 and 8.6.17, a stored cross-site scripting (XSS) vulnerability allows any authenticated user to upload an SVG fil…
- CVE-2026-30949HIGHCVSS 8.8EG 8.8✓ Fixed in 8.6.182026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keycloak authentication adapter does not validate the azp (authorized party) claim of Keycloak a…
- CVE-2026-30962MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.192026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.6 and 8.6.19, the validation for protected fields only checks top-level query keys. By wrapping a query constraint…
- CVE-2026-30965CRITICALCVSS 9.1EG 9.1✓ Fixed in 8.6.212026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker…
- CVE-2026-30966CRITICALCVSS 10.0EG 10.0✓ Fixed in 8.6.202026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field mappings such as role memberships, can be…
- CVE-2026-30967HIGHCVSS 8.8EG 8.8✓ Fixed in 8.6.222026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authentication adapter, when configured without the useridField option, only verifies th…
- CVE-2026-30972HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.232026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch re…
- CVE-2026-31800CRITICALCVSS 9.1EG 9.1✓ Fixed in 8.6.252026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.12 and 8.6.25, the _GraphQLConfig and _Audience internal classes can be read, modified, and deleted via the generi…
- CVE-2026-31828HIGHCVSS 8.8EG 8.8✓ Fixed in 8.6.262026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) …
- CVE-2026-31840CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.6.282026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject…
- CVE-2026-31856CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.6.292026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields usi…
- CVE-2026-31868MEDIUMCVSS 6.1EG 6.1✓ Fixed in 8.6.302026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.4 and 8.6.30, an attacker can upload a file with a file extension or content type that is not blocked by the defau…
- CVE-2026-31871CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.6.312026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment ope…
- CVE-2026-31872HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.322026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE c…
- CVE-2026-31875MEDIUMCVSS 5.9EG 5.9✓ Fixed in 8.6.332026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled for a user account, Parse Server generate…
- CVE-2026-31901MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.6.342026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endpoint (/verificationEmailRequest) returns distinct error responses dependi…
- CVE-2026-32098HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.352026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.9 and 8.6.35, an attacker can exploit LiveQuery subscriptions to infer the values of protected fields without dire…
- CVE-2026-32234MEDIUMCVSS 4.7EG 4.7✓ Fixed in 8.6.362026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.10 and 8.6.36, an attacker with access to the master key can inject malicious SQL via crafted field names used in …
- CVE-2026-32242HIGHCVSS 7.4EG 7.4✓ Fixed in 8.6.372026-03-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly ac…
- CVE-2026-32248CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.6.382026-03-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication …
- CVE-2026-32269MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.392026-03-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication adapter does not correctly validate app IDs when appidField and appIds ar…
- CVE-2026-32594HIGHCVSS 7.3EG 7.3✓ Fixed in 8.6.402026-03-16
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middlew…
- CVE-2026-32728HIGHCVSS 7.6EG 7.6✓ Fixed in 8.6.412026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attacker who is allowed to upload files can bypass the file extension filter by appending a MIME…
- CVE-2026-32742MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.6.422026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.17 and 8.6.42, an authenticated user can overwrite server-generated session fields (`sessionToken`, `expiresAt`, `…
- CVE-2026-32770HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.432026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.19 and 8.6.43, a remote attacker can crash the Parse Server by subscribing to a LiveQuery with an invalid regular …
- CVE-2026-32878HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.442026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.20 and 8.6.44, an attacker can bypass the default request keyword denylist protection and the class-level permissi…
- CVE-2026-32886HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.472026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.24 and 8.6.47, remote clients can crash the Parse Server process by calling a cloud function endpoint with a craft…
- CVE-2026-32943LOWCVSS 3.1EG 3.1✓ Fixed in 8.6.482026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.28 and 8.6.48, the password reset mechanism does not enforce single-use guarantees for reset tokens. When a user r…
- CVE-2026-32944HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.452026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.21 and 8.6.45, an unauthenticated attacker can crash the Parse Server process by sending a single request with dee…
- CVE-2026-33042MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.6.492026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.29 and 8.6.49, a user can sign up without providing credentials by sending an empty `authData` object, bypassing t…
- CVE-2026-33163MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.502026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the LiveQuery server le…
- CVE-2026-33323MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.6.512026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for resending email verification links return d…
- CVE-2026-33409CRITICALCVSS 9.1EG 9.1✓ Fixed in 8.6.522026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an attacker to log in as any user who has li…
- CVE-2026-33421MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.532026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.53 and 9.6.0-alpha.42, Parse Server's LiveQuery WebSocket interface does not enforce Class-Level Permission (CLP)…
- CVE-2026-33429MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.6.542026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.54 and 9.6.0-alpha.43, an attacker can subscribe to LiveQuery with a watch parameter targeting a protected field.…
- CVE-2026-33498HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.552026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.55 and 9.6.0-alpha.44, an attacker can send an unauthenticated HTTP request with a deeply nested query containing…
- CVE-2026-33508HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.562026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.56 and 9.6.0-alpha.45, Parse Server's LiveQuery component does not enforce the requestComplexity.queryDepth confi…
- CVE-2026-33527MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.6.572026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.57 and 9.6.0-alpha.48, an authenticated user can overwrite server-generated session fields such as expiresAt and …
- CVE-2026-33538HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.582026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.58 and 9.6.0-alpha.52, an unauthenticated attacker can cause denial of service by sending authentication requests…
- CVE-2026-33539HIGHCVSS 7.2EG 7.2✓ Fixed in 8.6.592026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.59 and 9.6.0-alpha.53, an attacker with master key access can execute arbitrary SQL statements on the PostgreSQL …
- CVE-2026-33624LOWCVSS 2.7EG 2.7✓ Fixed in 8.6.602026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54, an attacker who obtains a user's password and a single MFA recovery code can reuse that re…
- CVE-2026-33627MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.612026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, an authenticated user calling GET /users/me receives unsanitized auth data, including sens…
- CVE-2026-34215MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.632026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data, including MFA TOTP se…
- CVE-2026-34224MEDIUMCVSS 4.4EG 4.4✓ Fixed in 8.6.642026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a single MFA recovery c…
- CVE-2026-34363MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.6.652026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers process…
- CVE-2026-34373HIGHCVSS 8.8EG 8.8✓ Fixed in 8.6.662026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditionall…
- CVE-2026-34532CRITICALCVSS 9.1EG 9.1✓ Fixed in 8.6.672026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.co…
Check whether parse-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for parse-server CVEs against the assets you own.
Start Free Scan →