parse-server
npm117 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting parse-serverpage 3 of 3
- CVE-2026-34573HIGHCVSS 7.5EG 7.5fixed in 9.7.0-alpha.12 or 8.6.68, by version range2026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by se…
- CVE-2026-34574MEDIUMCVSS 5.4EG 5.4fixed in 9.7.0-alpha.14 or 8.6.69, by version range2026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, crea…
- CVE-2026-34595MEDIUMCVSS 4.3EG 4.3fixed in 9.7.0-alpha.16 or 8.6.70, by version range2026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields clas…
- CVE-2026-34784HIGHCVSS 7.5EG 7.5fixed in 9.7.1-alpha.1 or 8.6.71, by version range2026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its val…
- CVE-2026-35200MEDIUMCVSS 5.4EG 5.4fixed in 9.7.1-alpha.4 or 8.6.73, by version range2026-04-06
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .tx…
- CVE-2026-39321LOWCVSS 3.7EG 3.7fixed in 9.8.0-alpha.6 or 8.6.74, by version range2026-04-07
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.6 and 8.6.74, he login endpoint response time differs measurably depending on whether the submitted username or em…
- CVE-2026-39381MEDIUMCVSS 4.3EG 4.3fixed in 9.8.0-alpha.7 or 8.6.75, by version range2026-04-07
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.7 and 8.6.75, the GET /sessions/me endpoint returns _Session fields that the server operator explicitly configured…
- CVE-2026-43930MEDIUMCVSS 5.9EG 5.9fixed in 9.9.0-alpha.2 or 8.6.76, by version range2026-05-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two concurrent /login requ…
- CVE-2026-47138HIGHCVSS 8.7EG 8.7fixed in 9.9.1-alpha.1 or 8.6.77, by version range2026-05-23
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-known Parse Application ID can submit a si…
- CVE-2026-47248MEDIUMCVSS 6.9EG 6.9fixed in 9.9.1-alpha.2 or 8.6.78, by version range2026-05-29
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to unauthenticated callers throug…
- CVE-2026-50008MEDIUMCVSS 6.9EG 6.9fixed in 9.9.1-alpha.32026-06-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client access to a configured l…
- CVE-2026-53724LOWCVSS 2.1EG 2.1fixed in 9.9.1-alpha.4 or 8.6.79, by version range2026-06-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by appending a trailing dot to …
- CVE-2026-53725MEDIUMCVSS 5.9EG 5.9fixed in 9.9.1-alpha.52026-06-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _User class via Class-Level Permissions co…
- CVE-2026-53726MEDIUMCVSS 6.9EG 6.9fixed in 9.9.1-alpha.6 or 8.6.80, by version range2026-06-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the membership of a Relation fiel…
- CVE-2026-55778LOWCVSS 2.1EG 2.1fixed in 9.9.1-alpha.11 or 8.6.81, by version range2026-06-19
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUpload.fileExtensions blocklist could be bypassed by uploading a file with a non-st…
- CVE-2026-57480HIGHCVSS 8.7EG 8.7fixed in 9.9.1-alpha.12 or 8.6.82, by version range2026-07-08
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or LiveQuery query hand…
- CVE-2026-57481LOWCVSS 2.3EG 2.3fixed in 9.9.1-alpha.13 or 8.6.83, by version range2026-07-08
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a si…
Check whether parse-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for parse-server CVEs against the assets you own.
Book a Demo →