Manuel
|
b706c22cd9
|
fix: GeoPoint distance queries fail with an internal server error on MongoDB 8.3 and later (#10572)
|
2026-07-13 02:39:05 +02:00 |
|
Manuel
|
bea001e7ef
|
fix: Cloud Code beforeFind trigger context is not isolated from prototype pollution (#10570)
|
2026-07-11 03:45:38 +02:00 |
|
Manuel
|
cb9b54264d
|
fix: GraphQL error messages disclose pointer and relation target class names when public introspection is disabled ([GHSA-r2g6-4f6j-f6rf](https://github.com/parse-community/parse-server/security/advisories/GHSA-r2g6-4f6j-f6rf)) (#10568)
|
2026-07-11 00:28:29 +02:00 |
|
Manuel
|
d96c945b6d
|
fix: GraphQL error messages disclose required input field names when public introspection is disabled ([GHSA-2fgh-8j2g-w354](https://github.com/parse-community/parse-server/security/advisories/GHSA-2fgh-8j2g-w354)) (#10566)
|
2026-07-10 17:43:50 +02:00 |
|
Manuel
|
2625489a27
|
fix: GraphQL variable-coercion suggestions disclose schema to unauthenticated callers ([GHSA-9g8f-h8f3-hjcm](https://github.com/parse-community/parse-server/security/advisories/GHSA-9g8f-h8f3-hjcm)) (#10563)
|
2026-07-07 23:50:55 +02:00 |
|
Daniel
|
459786fd41
|
fix: NumberOrBoolean config option (cluster) value not coerced from env/CLI (#10531)
|
2026-07-07 15:37:06 +02:00 |
|
Manuel
|
cce91e5548
|
fix: Stored XSS via malformed Content-Type bypassing file upload extension blocklist ([GHSA-r899-h629-j84r](https://github.com/parse-community/parse-server/security/advisories/GHSA-r899-h629-j84r)) (#10521)
|
2026-06-25 11:09:12 +02:00 |
|
Manuel
|
4d3465c1b9
|
test: Rate limit requestMethods is scoped to the configured HTTP methods (#10520)
|
2026-06-20 03:42:22 +02:00 |
|
Manuel
|
816078fff7
|
feat: Add option to disallow aggregation pipelines for the read-only master key (#10517)
|
2026-06-20 01:11:51 +02:00 |
|
Manuel
|
e9c85dfe40
|
fix: LiveQuery discloses object data to a subscriber across an ACL read-access change ([GHSA-97pr-9hgg-3p8r](https://github.com/parse-community/parse-server/security/advisories/GHSA-97pr-9hgg-3p8r)) (#10515)
|
2026-06-19 02:13:55 +02:00 |
|
Manuel
|
1103c7a890
|
fix: Denial of service via exponential-time processing of deeply nested query operators ([GHSA-cgxm-vr2f-6fj8](https://github.com/parse-community/parse-server/security/advisories/GHSA-cgxm-vr2f-6fj8)) (#10511)
|
2026-06-17 16:21:23 +02:00 |
|
Manuel
|
be12a60d65
|
fix: Stored XSS via non-standard file extension bypassing file upload extension blocklist ([GHSA-v8x7-r927-cc93](https://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93)) (#10505)
|
2026-06-16 02:42:38 +02:00 |
|
Manuel
|
f8612109e3
|
fix: Middleware route checks do not match routing-equivalent path variants (trailing slash, case) (#10501)
|
2026-06-12 13:03:10 +02:00 |
|
Manuel
|
880e8e6929
|
fix: rateLimit on exact static routes is bypassed by appending a query string (#10500)
|
2026-06-11 03:11:49 +02:00 |
|
Manuel
|
3fad4fb1c4
|
fix: LiveQuery subscriptions leak when a client reuses a subscribe requestId (#10499)
|
2026-06-11 01:48:30 +02:00 |
|
Manuel
|
f12e1c3e31
|
fix: Cloud Function multipart requests bypass the maxUploadSize limit (#10498)
|
2026-06-06 02:43:56 +02:00 |
|
Manuel
|
78859a9bc7
|
docs: Clarify that rateLimit applies to REST API routes only and not to GraphQL operations (#10496)
|
2026-06-05 00:40:33 +02:00 |
|
Manuel
|
43658f1fd8
|
fix: Relation $relatedTo query bypasses protectedFields and owning-object ACL ([GHSA-wmwx-jr2p-4j4r](https://github.com/parse-community/parse-server/security/advisories/GHSA-wmwx-jr2p-4j4r)) (#10493)
|
2026-06-04 01:52:43 +02:00 |
|
Manuel
|
83e90edbe4
|
fix: Endpoints /login and /verifyPassword disclose MFA secrets and protected fields when _User get is denied ([GHSA-75v4-m273-5j49](https://github.com/parse-community/parse-server/security/advisories/GHSA-75v4-m273-5j49)) (#10492)
|
2026-06-03 16:41:16 +02:00 |
|
Manuel
|
66484ce8fd
|
fix: Stored XSS via trailing-dot filename bypassing file upload extension blocklist ([GHSA-7wqv-xjf3-x35v](https://github.com/parse-community/parse-server/security/advisories/GHSA-7wqv-xjf3-x35v)) (#10489)
|
2026-06-01 23:36:26 +02:00 |
|
Manuel
|
552c6dd754
|
fix: Server option routeAllowList is bypassable through batch sub-requests ([GHSA-p84r-h6rx-f2xr](https://github.com/parse-community/parse-server/security/advisories/GHSA-p84r-h6rx-f2xr)) (#10482)
|
2026-05-27 22:41:48 +02:00 |
|
Manuel
|
0ae0ed382b
|
test: GraphQL endpoint is exempt from routeAllowList by design (#10480)
|
2026-05-27 00:36:20 +02:00 |
|
Manuel
|
155123ade9
|
fix: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj](https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj)) (#10467)
|
2026-05-18 17:04:56 +02:00 |
|
Manuel
|
56c159ec96
|
fix: Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm](https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm)) (#10463)
|
2026-05-17 15:11:10 +01:00 |
|
Manuel
|
9fee1a0708
|
feat: Add installation deviceToken deduplication options (#10451)
|
2026-04-30 23:11:39 +01:00 |
|
Manuel
|
725be0d602
|
fix: MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) (#10448)
|
2026-04-26 03:10:27 +01:00 |
|
Manuel
|
f26700e39d
|
feat: Add rawValues and rawFieldNames options for aggregation queries (#10438)
|
2026-04-17 09:12:18 +01:00 |
|
Yogendra Singh
|
60a58ec11a
|
fix: Context mutations leak across requests in ParseServerRESTController (#10291)
|
2026-04-12 15:20:58 +01:00 |
|
Manuel
|
fd31159859
|
fix: Facebook Standard Login missing app ID validation (#10429)
|
2026-04-12 01:16:11 +01:00 |
|
Manuel
|
bf40004d25
|
feat: Add requestComplexity.subqueryLimit option to limit subquery results (#10420)
|
2026-04-10 16:49:34 +01:00 |
|
Manuel
|
18482e386c
|
feat: Add requestComplexity.allowRegex option to disable $regex query operator (#10418)
|
2026-04-09 18:12:12 +01:00 |
|
Antoine Cormouls
|
f208037b3b
|
refactor: Replace uuid dependency with native UUID (#10416)
|
2026-04-08 14:17:24 +01:00 |
|
Manuel
|
c0889c8575
|
fix: Master key does not bypass protectedFields on various endpoints (#10412)
|
2026-04-07 13:48:39 +01:00 |
|
Manuel
|
8a3db3b966
|
fix: Endpoints /login and /verifyPassword ignore _User protectedFields (#10409)
|
2026-04-07 13:01:11 +01:00 |
|
Manuel
|
c136e2b7ab
|
fix: Endpoint /upgradeToRevocableSession ignores _Session protectedFields (#10408)
|
2026-04-07 10:09:09 +01:00 |
|
Manuel
|
d5075758f6
|
fix: Endpoint /sessions/me bypasses _Session protectedFields ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) (#10406)
|
2026-04-06 17:46:32 +01:00 |
|
Manuel
|
531b9ab6dd
|
fix: Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) (#10398)
|
2026-04-05 17:48:57 +01:00 |
|
Manuel
|
a3f36a2ddb
|
feat: Add support for invoking Cloud Function with multipart/form-data protocol (#10395)
|
2026-04-04 17:46:51 +01:00 |
|
Manuel
|
fc117efa4d
|
feat: Add server option fileDownload to restrict file download (#10394)
|
2026-04-03 19:41:42 +01:00 |
|
Manuel
|
7d8b367e0b
|
fix: Maintenance key IP mismatch silently downgrades to regular auth instead of rejecting (#10391)
|
2026-04-03 17:36:27 +01:00 |
|
Manuel
|
f2d06e7b95
|
feat: Add route block with new server option routeAllowList (#10389)
|
2026-04-03 16:08:18 +01:00 |
|
Manuel
|
dd7cc41a95
|
fix: File upload Content-Type override via extension mismatch ([GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc)) (#10383)
|
2026-04-02 02:19:26 +01:00 |
|
Manuel
|
ead12bd1df
|
fix: Session field guard bypass via falsy values for ACL and user fields (#10382)
|
2026-04-01 21:25:30 +01:00 |
|
Manuel
|
66350964c8
|
fix: Nested batch sub-requests cause unclear error (#10371)
|
2026-04-01 14:35:25 +01:00 |
|
Manuel
|
a0b0c69fc4
|
fix: Streaming file download bypasses afterFind file trigger authorization ([GHSA-hpm8-9qx6-jvwv](https://github.com/parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv)) (#10361)
|
2026-03-31 00:17:57 +01:00 |
|
Manuel
|
aea7596cd2
|
feat: Extend storage adapter interface to optionally return matchedCount and modifiedCount from DatabaseController.update with many: true (#10353)
|
2026-03-30 01:09:10 +01:00 |
|
Manuel
|
d5f5128ade
|
fix: Cloud Code trigger context vulnerable to prototype pollution (#10352)
|
2026-03-30 00:21:18 +01:00 |
|
Manuel
|
f63fd1a3fe
|
fix: LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) (#10350)
|
2026-03-29 19:36:52 +01:00 |
|
Manuel
|
63c37c49c7
|
fix: Batch login sub-request rate limit uses IP-based keying (#10349)
|
2026-03-29 16:08:36 +01:00 |
|
Manuel
|
90802969fc
|
fix: Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) (#10347)
|
2026-03-29 04:55:39 +01:00 |
|