VYPR

Bitnami package

parse

pkg:bitnami/parse

Vulnerabilities (115)

  • CVE-2026-32878HigMar 18, 2026
    affected < 8.6.44fixed 8.6.44

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.20 and 8.6.44, an attacker can bypass the default request keyword denylist protection and the class-level permission for adding fields by sending a crafted

  • CVE-2026-32770MedMar 18, 2026
    affected < 8.6.43fixed 8.6.43

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.19 and 8.6.43, a remote attacker can crash the Parse Server by subscribing to a LiveQuery with an invalid regular expression pattern. The server process te

  • CVE-2026-32742MedMar 18, 2026
    affected < 8.6.42fixed 8.6.42

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.17 and 8.6.42, an authenticated user can overwrite server-generated session fields (`sessionToken`, `expiresAt`, `createdWith`) when creating a session obj

  • CVE-2026-32728HigMar 18, 2026
    affected < 8.6.41fixed 8.6.41

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attacker who is allowed to upload files can bypass the file extension filter by appending a MIME parameter (e.g. `;charset=utf-8`) to the

  • CVE-2026-32594HigMar 16, 2026
    affected < 8.6.40fixed 8.6.40

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middleware chain that enforces authentication, i

  • CVE-2026-32269MedMar 12, 2026
    affected >= 8.0.2, < 8.6.39fixed 8.6.39

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication adapter does not correctly validate app IDs when appidField and appIds are configured. During app ID validation, a

  • CVE-2026-32248CriMar 12, 2026
    affected < 8.6.38fixed 8.6.38

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider that does not validate the forma

  • CVE-2026-32242HigMar 12, 2026
    affected < 8.6.37fixed 8.6.37

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly across all OAuth2 provider configurations.

  • CVE-2026-32234MedMar 11, 2026
    affected < 8.6.36fixed 8.6.36

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.10 and 8.6.36, an attacker with access to the master key can inject malicious SQL via crafted field names used in query constraints when Parse Server is co

  • CVE-2026-32098HigMar 11, 2026
    affected < 8.6.35fixed 8.6.35

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.9 and 8.6.35, an attacker can exploit LiveQuery subscriptions to infer the values of protected fields without directly receiving them. By subscribing with

  • CVE-2026-31901MedMar 11, 2026
    affected < 8.6.34fixed 8.6.34

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endpoint (/verificationEmailRequest) returns distinct error responses depending on whether an email address belongs to

  • CVE-2026-31875MedMar 11, 2026
    affected < 8.6.33fixed 8.6.33

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled for a user account, Parse Server generates two single-use recovery codes. These co

  • CVE-2026-31872HigMar 11, 2026
    affected < 8.6.32fixed 8.6.32

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE clauses and sort parameters. An attacker c

  • CVE-2026-31871CriMar 11, 2026
    affected < 8.6.31fixed 8.6.31

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot

  • CVE-2026-31868MedMar 11, 2026
    affected < 8.6.30fixed 8.6.30

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.4 and 8.6.30, an attacker can upload a file with a file extension or content type that is not blocked by the default configuration of the Parse Server file

  • CVE-2026-31856CriMar 11, 2026
    affected < 8.6.29fixed 8.6.29

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter). Th

  • CVE-2026-31840CriMar 11, 2026
    affected < 8.6.28fixed 8.6.28

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject SQL into the PostgreSQL database through

  • CVE-2026-31828HigMar 10, 2026
    affected < 8.6.26fixed 8.6.26

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) is interpolated directly into LDAP Distin

  • CVE-2026-31800CriMar 10, 2026
    affected < 8.6.25fixed 8.6.25

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.12 and 8.6.25, the _GraphQLConfig and _Audience internal classes can be read, modified, and deleted via the generic /classes/_GraphQLConfig and /classes/_A

  • CVE-2026-30972HigMar 10, 2026
    affected < 8.6.23fixed 8.6.23

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch request endpoint (/batch) processes sub-req

Page 3 of 6