parse-server
npm117 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting parse-serverpage 3 of 3
- CVE-2026-34573HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.682026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by se…
- CVE-2026-34574MEDIUMCVSS 5.4EG 5.4✓ Fixed in 8.6.692026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, crea…
- CVE-2026-34595MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.6.702026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields clas…
- CVE-2026-34784HIGHCVSS 7.5EG 7.5✓ Fixed in 8.6.712026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its val…
- CVE-2026-35200MEDIUMCVSS 5.4EG 5.4✓ Fixed in 8.6.732026-04-06
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .tx…
- CVE-2026-39321LOWCVSS 3.7EG 3.7✓ Fixed in 8.6.742026-04-07
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.6 and 8.6.74, he login endpoint response time differs measurably depending on whether the submitted username or em…
- CVE-2026-39381MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.6.752026-04-07
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.7 and 8.6.75, the GET /sessions/me endpoint returns _Session fields that the server operator explicitly configured…
- CVE-2026-43930MEDIUMCVSS 5.9EG 5.9✓ Fixed in 8.6.762026-05-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two concurrent /login requ…
- CVE-2026-47138HIGHCVSS 8.7EG 8.7✓ Fixed in 8.6.772026-05-23
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-known Parse Application ID can submit a si…
- CVE-2026-47248MEDIUMCVSS 6.9EG 6.9✓ Fixed in 8.6.782026-05-29
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to unauthenticated callers throug…
- CVE-2026-50008MEDIUMCVSS 6.9EG 6.9✓ Fixed in 9.9.1-alpha.32026-06-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client access to a configured l…
- CVE-2026-53724LOWCVSS 2.1EG 2.1✓ Fixed in 8.6.792026-06-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by appending a trailing dot to …
- CVE-2026-53725MEDIUMCVSS 5.9EG 5.9✓ Fixed in 9.9.1-alpha.52026-06-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _User class via Class-Level Permissions co…
- CVE-2026-53726MEDIUMCVSS 6.9EG 6.9✓ Fixed in 8.6.802026-06-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the membership of a Relation fiel…
- CVE-2026-55778LOWCVSS 2.1EG 2.1✓ Fixed in 8.6.812026-06-19
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUpload.fileExtensions blocklist could be bypassed by uploading a file with a non-st…
- CVE-2026-57480HIGHCVSS 8.7EG 8.7✓ Fixed in 8.6.822026-07-08
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or LiveQuery query hand…
- CVE-2026-57481LOWCVSS 2.3EG 2.3✓ Fixed in 8.6.832026-07-08
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a si…
Check whether parse-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for parse-server CVEs against the assets you own.
Start Free Scan →