6.5
CVE-2026-32269
- EPSS 0.28%
- Veröffentlicht 12.03.2026 19:43:23
- Zuletzt bearbeitet 13.03.2026 18:59:01
- Erkennungen
Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication adapter does not correctly validate app IDs when appidField and appIds are configured. During app ID validation, a malformed value is sent to the token introspection endpoint instead of the user's actual access token. Depending on the introspection endpoint's behavior, this could either cause all OAuth2 logins to fail, or allow authentication from disallowed app contexts if the endpoint returns valid-looking data for the malformed request. Deployments using the OAuth2 adapter with appidField and appIds configured are affected. This vulnerability is fixed in 9.6.0-alpha.13 and 8.6.39.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Parseplatform ≫ Parse-server SwPlatform node.js Version >= 8.0.2 < 8.6.39
Parseplatform ≫ Parse-server SwPlatform node.js Version >= 9.0.0 < 9.6.0
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha10 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha11 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha12 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha2 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha3 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha4 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha5 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha6 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha7 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha8 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha9 SwPlatform node.js
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.191 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| security-advisories@github.com | 6.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-683 Function Call With Incorrect Order of Arguments
The product calls a function, procedure, or routine, but the caller specifies the arguments in an incorrect order, leading to resultant weaknesses.
https://github.com/parse-community/parse-server/security/advisories/GHSA-69xg-f649-w5g2
https://github.com/parse-community/parse-server/releases/tag/8.6.39
https://github.com/parse-community/parse-server/releases/tag/9.6.0-alpha.13