Security: parse-community/parse-server
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Protected fields bypass via logical query operatorsGHSA-72hp-qff8-4pvv published
Mar 10, 2026 by mtrezzaHigh -
NoSQL injection via token type in password reset and email verification endpointsGHSA-vgjh-hmwf-c588 published
Mar 10, 2026 by mtrezzaHigh -
Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain ResolutionGHSA-5j86-7r7m-p8h6 published
Mar 7, 2026 by mtrezzaHigh -
Denylist `requestKeywordDenylist` keyword scan bypass through nested object placementGHSA-q342-9w2p-57fp published
Mar 7, 2026 by mtrezzaModerate -
JWT audience validation bypass in Google, Apple, and Facebook authentication adaptersGHSA-x6fw-778m-wr9v published
Mar 7, 2026 by mtrezzaCritical -
Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQueryGHSA-mf3j-86qx-cq5j published
Mar 7, 2026 by mtrezzaHigh -
`PagesRouter` path traversal allows reading files outside configured pages directoryGHSA-hm3f-q6rw-m6wh published
Mar 7, 2026 by mtrezzaModerate -
GraphQL `__type` introspection bypass via inline fragments when public introspection is disabledGHSA-q5q9-2rhp-33qw published
Mar 7, 2026 by mtrezzaModerate -
File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorizationGHSA-hwx8-q9cg-mqmc published
Mar 7, 2026 by mtrezzaModerate -
Malformed `$regex` query leaks database error details in API responseGHSA-9cp7-3q5w-j92g published
Mar 5, 2026 by mtrezzaModerate