CVE-2026-39381
- EPSS 0.04%
- Veröffentlicht 07.04.2026 19:51:03
- Zuletzt bearbeitet 15.04.2026 15:57:20
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.7 and 8.6.75, the GET /sessions/me endpoint returns _Session fields that the server operator explicitly configured as protect...
CVE-2026-39321
- EPSS 0.03%
- Veröffentlicht 07.04.2026 18:16:43
- Zuletzt bearbeitet 15.04.2026 17:20:11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.6 and 8.6.74, he login endpoint response time differs measurably depending on whether the submitted username or email exists ...
CVE-2026-35200
- EPSS 0.03%
- Veröffentlicht 06.04.2026 19:47:27
- Zuletzt bearbeitet 07.04.2026 18:01:08
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .txt) but with...
CVE-2026-34784
- EPSS 0.04%
- Veröffentlicht 31.03.2026 19:39:54
- Zuletzt bearbeitet 01.04.2026 17:06:54
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its validators on ...
CVE-2026-34215
- EPSS 0.05%
- Veröffentlicht 31.03.2026 19:34:50
- Zuletzt bearbeitet 03.04.2026 17:16:43
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data, including MFA TOTP secrets, reco...
CVE-2026-34595
- EPSS 0.03%
- Veröffentlicht 31.03.2026 15:10:06
- Zuletzt bearbeitet 02.04.2026 17:12:56
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields class-level per...
CVE-2026-34574
- EPSS 0.03%
- Veröffentlicht 31.03.2026 15:08:31
- Zuletzt bearbeitet 02.04.2026 17:23:16
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by...
CVE-2026-34573
- EPSS 0.05%
- Veröffentlicht 31.03.2026 15:06:33
- Zuletzt bearbeitet 02.04.2026 17:31:49
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by sending a cra...
CVE-2026-34532
- EPSS 0.04%
- Veröffentlicht 31.03.2026 14:42:10
- Zuletzt bearbeitet 02.04.2026 18:01:28
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" ...
CVE-2026-34373
- EPSS 0.02%
- Veröffentlicht 31.03.2026 14:38:16
- Zuletzt bearbeitet 02.04.2026 18:40:32
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditionally allows cr...