Parse-Community Parse-Server vulnerabilities
123 known vulnerabilities affecting parse-community/parse-server.
Total CVEs
123
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL20HIGH45MEDIUM48LOW10
Vulnerabilities
Page 4 of 7
CVE-2026-32770P3HIGHCVSS 7.5v>= 9.0.0, < 9.6.0-alpha.19fixed in 8.6.432026-03-18
CVE-2026-32770 [HIGH] CWE-248 CVE-2026-32770: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.19 and 8.6.43, a remote attacker can crash the Parse Server by subscribing to a LiveQuery with an invalid regular expression pattern. The server process terminates when the invalid pattern reaches the regex engine during subscri
ghsanvdosv
CVE-2021-47986P3HIGHCVSS 7.5fixed in 4.10.02026-06-25
CVE-2021-47986 [HIGH] CWE-494 CVE-2021-47986: Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were p
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.
nvd
CVE-2025-68150P3MEDIUMCVSS 6.5fixed in 8.6.2v>= 9.0.0, < 9.1.1-alpha.12025-12-16
CVE-2025-68150 [MEDIUM] CWE-918 CVE-2025-68150: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, the Instagram authentication adapter allows clients to specify a custom API URL via the `apiURL` parameter in `authData`. This enables SSRF attacks and possibly authentication bypass if malicious endpoint
ghsanvdosv
CVE-2026-101042P3MEDIUMCVSS 6.4≥ 9.0.0, < 9.10.1-alpha.10≥ 8.0.2, < 8.6.912026-09-27
CVE-2026-101042 [MEDIUM] CWE-287 CVE-2026-101042: Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 <
Parse Server is an open-source backend server. In versions >= 9.0.0 = 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization code with the external provider on signup and on provider linking, but not when authentication d
nvd
CVE-2022-31083P3HIGHCVSS 7.5fixed in 4.0.11v>= 5.0.0, < 5.2.22022-06-17
CVE-2022-31083 [HIGH] CWE-287 CVE-2022-31083: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, authentication could potentially be bypassed by making a fake certificate accessible via certain Apple domains and pr
ghsanvdosv
CVE-2022-24901P3HIGHCVSS 7.5fixed in 4.10.10v>= 5.0.0, < 5.2.12022-05-04
CVE-2022-24901 [HIGH] CWE-287 CVE-2022-24901: Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter all
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.
ghsanvdosv
CVE-2026-32728P3HIGHCVSS 7.6v>= 9.0.0, < 9.6.0-alpha.15fixed in 8.6.412026-03-18
CVE-2026-32728 [HIGH] CWE-79 CVE-2026-32728: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attacker who is allowed to upload files can bypass the file extension filter by appending a MIME parameter (e.g. `;charset=utf-8`) to the `Content-Type` header. This causes the extension validation to fail match
ghsanvdosv
CVE-2026-47248P3MEDIUMCVSS 6.9fixed in 8.6.78v>= 9.0.0, < 9.9.1-alpha.22026-06-12
CVE-2026-47248 [MEDIUM] CWE-209 CVE-2026-47248: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to unauthenticated callers through Did you mean ...? suggestions embedded in GraphQL validation-error messages. An unauthenticated caller who kno
nvd
CVE-2026-64627P3MEDIUMCVSS 6.9≥ 9.0.0, < 9.10.0-alpha.4fixed in 8.6.852026-07-21
CVE-2026-64627 [MEDIUM] CWE-209 CVE-2026-64627: Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema dis
Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection: false, the default), schema-derived 'Did you mean ...?' suggestions were still returned in GraphQL error messages produced during va
nvd
CVE-2026-33627P3MEDIUMCVSS 6.5fixed in 8.6.61v>= 9.0.0, < 9.6.0-alpha.552026-03-24
CVE-2026-33627 [MEDIUM] CWE-200 CVE-2026-33627: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, an authenticated user calling GET /users/me receives unsanitized auth data, including sensitive credentials such as MFA TOTP secrets and recovery codes. The endpoint internally uses master-level authent
ghsanvdosv
CVE-2021-39187P3HIGHCVSS 7.5fixed in 4.10.32021-09-02
CVE-2021-39187 [HIGH] CWE-74 CVE-2021-39187: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes when if a query request contains an invalid value for the `explain` option. This is due to a bug in the MongoDB Node.js driver which throws an exception that Parse Server cannot catch. There is a patch fo
ghsanvdosv
CVE-2026-33421P3MEDIUMCVSS 6.5fixed in 8.6.53v>= 9.0.0, < 9.6.0-alpha.422026-03-24
CVE-2026-33421 [MEDIUM] CWE-863 CVE-2026-33421: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.53 and 9.6.0-alpha.42, Parse Server's LiveQuery WebSocket interface does not enforce Class-Level Permission (CLP) pointer permissions (readUserFields and pointerFields). Any authenticated user can subscribe to LiveQuery event
ghsanvdosv
CVE-2026-100632P3MEDIUMCVSS 6.5≥ 9.0.0, < 9.10.1-alpha.8fixed in 8.6.892026-09-26
CVE-2026-100632 [MEDIUM] CWE-200 CVE-2026-100632: Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in ver
Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own session token the event payload
nvd
CVE-2026-66009P3MEDIUMCVSS 6.3≥ 9.0.0, < 9.10.0-alpha.5≥ 8.2.2, < 8.6.862026-07-24
CVE-2026-66009 [MEDIUM] CWE-209 CVE-2026-66009: Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL valid
Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). A client holding only the public application id — with no user session, master key, or maintenance
nvd
CVE-2021-41109P3HIGHCVSS 7.5fixed in 4.10.42021-09-30
CVE-2021-41109 [HIGH] CWE-200 CVE-2021-41109: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.4, for regular (non-LiveQuery) queries, the session token is removed from the response, but for LiveQuery payloads it is currently not. If a user has a LiveQuery subscription on the `Parse.User` class, all session tokens create
ghsanvdosv
CVE-2022-31089P3HIGHCVSS 7.5fixed in 4.10.12v>=5.0.0, < 5.2.32022-06-27
CVE-2022-31089 [HIGH] CWE-252 CVE-2022-31089: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions certain types of invalid files requests are not handled properly and can crash the server. If you are running multiple Parse Server instances in a cluster, the availability impact may be low; if you are running Parse Server as s
ghsanvdosv
CVE-2026-30962P3MEDIUMCVSS 6.5v>= 9.0.0 < 9.5.2-alpha.6fixed in 8.6.192026-03-10
CVE-2026-30962 [MEDIUM] CWE-284 CVE-2026-30962: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.6 and 8.6.19, the validation for protected fields only checks top-level query keys. By wrapping a query constraint on a protected field inside a logical operator, the check is bypassed entirely. This allows any authenticated u
ghsanvdosv
CVE-2026-32269P3MEDIUMCVSS 6.5v>= 9.0.0, < 9.6.0-alpha.13v>= 8.0.2, < 8.6.392026-03-12
CVE-2026-32269 [MEDIUM] CWE-683 CVE-2026-32269: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication adapter does not correctly validate app IDs when appidField and appIds are configured. During app ID validation, a malformed value is sent to the token introspection endpoint instead of
ghsanvdosv
CVE-2022-39313P3HIGHCVSS 7.5fixed in 4.10.17v>= 5.0.0, < 5.2.82022-10-24
CVE-2022-39313 [HIGH] CWE-1284 CVE-2022-39313: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.17, and prior to 5.2.8 on the 5.x branch, crash when a file download request is received with an invalid byte range, resulting in a Denial of Service. This issue has been patched in versions 4.10.17, and 5.2.8. There are no k
ghsanvdosv
CVE-2025-64502P3MEDIUMCVSS 6.9fixed in 8.5.0-alpha.52025-11-10
CVE-2025-64502 [MEDIUM] CWE-201 CVE-2025-64502: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `explain()` method provides detailed information about query execution plans, including index usage, collection scanning behavior, and performance metrics. Prior to version 8.5.0-alpha.5, Parse Server permits any client to execute expl
ghsanvdosv