VYPR

Bitnami package

parse

pkg:bitnami/parse

Vulnerabilities (123)

  • CVE-2026-101042MedSep 27, 2026
    affected >= 8.0.2, < 8.6.91fixed 8.6.91

    Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization code

  • CVE-2026-100632MedSep 26, 2026
    affected < 8.6.89fixed 8.6.89

    Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a

  • CVE-2026-100631HigSep 26, 2026
    affected < 8.6.90fixed 8.6.90

    Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to buil

  • CVE-2026-87806HigSep 9, 2026
    affected < 8.6.88fixed 8.6.88

    Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter. The adapter forwarded the client-supplied password to the directory without verifying that a password had been supplied, and treated any non

  • CVE-2026-66009MedJul 24, 2026
    affected >= 8.2.2, < 8.6.86fixed 8.6.86

    Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). A client holding only the p

  • CVE-2026-66008MedJul 24, 2026
    affected >= 8.2.2, < 8.6.87fixed 8.6.87

    Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disabled (graphQLPublicIntrospection: false, the defau

  • CVE-2026-64627MedJul 21, 2026
    affected < 8.6.85fixed 8.6.85

    Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection: false, the default), schema-derived 'Did you mean ...?' sugge

  • CVE-2026-61448LowJul 11, 2026
    affected < 8.6.84fixed 8.6.84

    Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-supplied Content-Type. A malformed Conten

  • CVE-2026-57481LowJul 8, 2026
    affected < 8.6.83fixed 8.6.83

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field an

  • CVE-2026-57480HigJul 8, 2026
    affected < 8.6.82fixed 8.6.82

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or LiveQuery query handling could trigger exponential-time proce

  • CVE-2026-55778LowJul 8, 2026
    affected < 8.6.81fixed 8.6.81

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUpload.fileExtensions blocklist could be bypassed by uploading a file with a non-standard or compound extension and dangerou

  • CVE-2021-47987HigJun 25, 2026
    affected < 4.10.0fixed 4.10.0

    Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed

  • CVE-2021-47986HigJun 25, 2026
    affected < 4.10.0fixed 4.10.0

    Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unrevi

  • CVE-2026-53726MedJun 12, 2026
    affected < 8.6.80fixed 8.6.80

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the membership of a Relation field even when that field was hidden from th

  • CVE-2026-53725MedJun 12, 2026
    affected >= 9.8.0, < 9.9.1fixed 9.9.1

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _User class via Class-Level Permissions could expose sensitive user data through th

  • CVE-2026-53724LowJun 12, 2026
    affected < 8.6.79fixed 8.6.79

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by appending a trailing dot to a filename whose extension would otherwis

  • CVE-2026-50008MedJun 12, 2026
    affected >= 9.8.0, < 9.9.1fixed 9.9.1

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client access to a configured list of REST API routes. The check is only

  • CVE-2026-47248MedJun 12, 2026
    affected < 8.6.78fixed 8.6.78

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to unauthenticated callers through Did you mean ...? suggestions embedded

  • CVE-2026-47138HigJun 12, 2026
    affected < 8.6.77fixed 8.6.77

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-known Parse Application ID can submit a single HTTP request whose client SDK versio

  • CVE-2026-43930MedMay 12, 2026
    affected < 8.6.76fixed 8.6.76

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two concurrent /login requests carrying the same OTP to both succee

Page 1 of 7

VYPR — Vulnerability Intelligence