Security: parse-community/parse-server
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unauthenticated deletion of installation records via operator injection in device token deduplicationGHSA-cc6h-c8m4-hgrx published
Sep 9, 2026 by mtrezzaHigh -
LiveQuery discloses protected fields by resolving an incomplete subscriber identityGHSA-9jpp-xhh6-75mf published
Sep 8, 2026 by mtrezzaHigh -
Account takeover via empty password in LDAP auth adapterGHSA-863r-39r9-vfcf published
Aug 25, 2026 by mtrezzaCritical -
GraphQL error messages disclose pointer and relation target class names when public introspection is disabledGHSA-r2g6-4f6j-f6rf published
Jul 10, 2026 by mtrezzaModerate -
GraphQL error messages disclose required input field names when public introspection is disabledGHSA-2fgh-8j2g-w354 published
Jul 10, 2026 by mtrezzaModerate -
Stored XSS via malformed Content-Type bypassing file upload extension blocklistGHSA-r899-h629-j84r published
Jun 25, 2026 by mtrezzaLow -
LiveQuery discloses object data to a subscriber across an ACL read-access changeGHSA-97pr-9hgg-3p8r published
Jun 19, 2026 by mtrezzaLow -
Denial of service via exponential-time processing of deeply nested query operatorsGHSA-cgxm-vr2f-6fj8 published
Jun 17, 2026 by mtrezzaHigh -
Stored XSS via non-standard file extension bypassing file upload extension blocklistGHSA-v8x7-r927-cc93 published
Jun 16, 2026 by mtrezzaLow -
GraphQL variable-coercion suggestions disclose schema to unauthenticated callersGHSA-9g8f-h8f3-hjcm published
Jul 8, 2026 by mtrezzaModerate