VYPR

Bitnami package

parse

pkg:bitnami/parse

Vulnerabilities (115)

  • CVE-2026-30967HigMar 10, 2026
    affected < 8.6.22fixed 8.6.22

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authentication adapter, when configured without the useridField option, only verifies that a token is active via the provider's t

  • CVE-2026-30966CriMar 10, 2026
    affected < 8.6.20fixed 8.6.20

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field mappings such as role memberships, can be directly accessed via the REST API or Gr

  • CVE-2026-30965CriMar 10, 2026
    affected < 8.6.21fixed 8.6.21

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltrate session tokens of other us

  • CVE-2026-30962MedMar 10, 2026
    affected < 8.6.19fixed 8.6.19

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.6 and 8.6.19, the validation for protected fields only checks top-level query keys. By wrapping a query constraint on a protected field inside a logical op

  • CVE-2026-30949HigMar 10, 2026
    affected < 8.6.18fixed 8.6.18

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keycloak authentication adapter does not validate the azp (authorized party) claim of Keycloak access tokens against the configured clien

  • CVE-2026-30948MedMar 10, 2026
    affected < 8.6.17fixed 8.6.17

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.4 and 8.6.17, a stored cross-site scripting (XSS) vulnerability allows any authenticated user to upload an SVG file containing JavaScript. The file is serv

  • CVE-2026-30947HigMar 10, 2026
    affected < 8.6.16fixed 8.6.16

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.3 and 8.6.16, class-level permissions (CLP) are not enforced for LiveQuery subscriptions. An unauthenticated or unauthorized client can subscribe to any Li

  • CVE-2026-30946HigMar 10, 2026
    affected < 8.6.15fixed 8.6.15

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alpha.2 and 8.6.15, an unauthenticated attacker can exhaust Parse Server resources (CPU, memory, database connections) through crafted queries that exploit the lack

  • CVE-2026-30941HigMar 10, 2026
    affected < 8.6.14fixed 8.6.14

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1, NoSQL injection vulnerability allows an unauthenticated attacker to inject MongoDB query operators via the token field in the password reset

  • CVE-2026-30939HigMar 10, 2026
    affected < 8.6.13fixed 8.6.13

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13 and 9.5.1-alpha.2, an unauthenticated attacker can crash the Parse Server process by calling a Cloud Function endpoint with a prototype property name as the fun

  • CVE-2026-30938MedMar 10, 2026
    affected < 8.6.12fixed 8.6.12

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.12 and 9.5.1-alpha.1, the requestKeywordDenylist security control can be bypassed by placing any nested object or array before a prohibited keyword in the request

  • CVE-2026-30925HigMar 10, 2026
    affected < 8.6.11fixed 8.6.11

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a crafted $regex pattern that causes catastrophic backtracking, blocking the Node.js ev

  • CVE-2026-30863CriMar 7, 2026
    affected < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook authentication adapters use JWT verification to validate identity tokens. When the adapter's audien

  • CVE-2026-30854MedMar 7, 2026
    affected >= 9.3.1, < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3.1-alpha.3 to before version 9.5.0-alpha.10, when graphQLPublicIntrospection is disabled, __type queries nested inside inline fragments (e.g. ... on Query { __t

  • CVE-2026-30850MedMar 7, 2026
    affected < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.9 and 9.5.0-alpha.9, the file metadata endpoint (GET /files/:appId/metadata/:filename) does not enforce beforeFind / afterFind file triggers. When these t

  • CVE-2026-30848LowMar 7, 2026
    affected < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.8 and 9.5.0-alpha.8, the PagesRouter static file serving route is vulnerable to a path traversal attack that allows unauthenticated reading of files outsi

  • CVE-2026-30835MedMar 6, 2026
    affected < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.7 and 9.5.0-alpha.6, malformed $regex query parameter (e.g. [abc) causes the database to return a structured error object that is passed unsanitized thro

  • CVE-2026-30229HigMar 6, 2026
    affected < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.6 and 9.5.0-alpha.4, the readOnlyMasterKey can call POST /loginAs to obtain a valid session token for any user. This allows a read-only credential to impe

  • CVE-2026-30228MedMar 6, 2026
    affected < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.5 and 9.5.0-alpha.3, the readOnlyMasterKey can be used to create and delete files via the Files API (POST /files/:filename, DELETE /files/:filename). This

  • CVE-2026-29182HigMar 6, 2026
    affected < 9.4.1fixed 9.4.1

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.4 and 9.4.1-alpha.3, Parse Server's readOnlyMasterKey option allows access with master-level read privileges but is documented to deny all write operation

Page 4 of 6