1950 Commits
Author SHA1 Message Date
Manuel b706c22cd9 fix: GeoPoint distance queries fail with an internal server error on MongoDB 8.3 and later (#10572) 2026-07-13 02:39:05 +02:00
Manuel bea001e7ef fix: Cloud Code beforeFind trigger context is not isolated from prototype pollution (#10570) 2026-07-11 03:45:38 +02:00
Manuel cb9b54264d fix: GraphQL error messages disclose pointer and relation target class names when public introspection is disabled ([GHSA-r2g6-4f6j-f6rf](https://github.com/parse-community/parse-server/security/advisories/GHSA-r2g6-4f6j-f6rf)) (#10568) 2026-07-11 00:28:29 +02:00
Manuel d96c945b6d fix: GraphQL error messages disclose required input field names when public introspection is disabled ([GHSA-2fgh-8j2g-w354](https://github.com/parse-community/parse-server/security/advisories/GHSA-2fgh-8j2g-w354)) (#10566) 2026-07-10 17:43:50 +02:00
Manuel 2625489a27 fix: GraphQL variable-coercion suggestions disclose schema to unauthenticated callers ([GHSA-9g8f-h8f3-hjcm](https://github.com/parse-community/parse-server/security/advisories/GHSA-9g8f-h8f3-hjcm)) (#10563) 2026-07-07 23:50:55 +02:00
Daniel 459786fd41 fix: NumberOrBoolean config option (cluster) value not coerced from env/CLI (#10531) 2026-07-07 15:37:06 +02:00
Manuel cce91e5548 fix: Stored XSS via malformed Content-Type bypassing file upload extension blocklist ([GHSA-r899-h629-j84r](https://github.com/parse-community/parse-server/security/advisories/GHSA-r899-h629-j84r)) (#10521) 2026-06-25 11:09:12 +02:00
Manuel 4d3465c1b9 test: Rate limit requestMethods is scoped to the configured HTTP methods (#10520) 2026-06-20 03:42:22 +02:00
Manuel 816078fff7 feat: Add option to disallow aggregation pipelines for the read-only master key (#10517) 2026-06-20 01:11:51 +02:00
Manuel e9c85dfe40 fix: LiveQuery discloses object data to a subscriber across an ACL read-access change ([GHSA-97pr-9hgg-3p8r](https://github.com/parse-community/parse-server/security/advisories/GHSA-97pr-9hgg-3p8r)) (#10515) 2026-06-19 02:13:55 +02:00
Manuel 1103c7a890 fix: Denial of service via exponential-time processing of deeply nested query operators ([GHSA-cgxm-vr2f-6fj8](https://github.com/parse-community/parse-server/security/advisories/GHSA-cgxm-vr2f-6fj8)) (#10511) 2026-06-17 16:21:23 +02:00
Manuel be12a60d65 fix: Stored XSS via non-standard file extension bypassing file upload extension blocklist ([GHSA-v8x7-r927-cc93](https://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93)) (#10505) 2026-06-16 02:42:38 +02:00
Manuel f8612109e3 fix: Middleware route checks do not match routing-equivalent path variants (trailing slash, case) (#10501) 2026-06-12 13:03:10 +02:00
Manuel 880e8e6929 fix: rateLimit on exact static routes is bypassed by appending a query string (#10500) 2026-06-11 03:11:49 +02:00
Manuel 3fad4fb1c4 fix: LiveQuery subscriptions leak when a client reuses a subscribe requestId (#10499) 2026-06-11 01:48:30 +02:00
Manuel f12e1c3e31 fix: Cloud Function multipart requests bypass the maxUploadSize limit (#10498) 2026-06-06 02:43:56 +02:00
Manuel 78859a9bc7 docs: Clarify that rateLimit applies to REST API routes only and not to GraphQL operations (#10496) 2026-06-05 00:40:33 +02:00
Manuel 43658f1fd8 fix: Relation $relatedTo query bypasses protectedFields and owning-object ACL ([GHSA-wmwx-jr2p-4j4r](https://github.com/parse-community/parse-server/security/advisories/GHSA-wmwx-jr2p-4j4r)) (#10493) 2026-06-04 01:52:43 +02:00
Manuel 83e90edbe4 fix: Endpoints /login and /verifyPassword disclose MFA secrets and protected fields when _User get is denied ([GHSA-75v4-m273-5j49](https://github.com/parse-community/parse-server/security/advisories/GHSA-75v4-m273-5j49)) (#10492) 2026-06-03 16:41:16 +02:00
Manuel 66484ce8fd fix: Stored XSS via trailing-dot filename bypassing file upload extension blocklist ([GHSA-7wqv-xjf3-x35v](https://github.com/parse-community/parse-server/security/advisories/GHSA-7wqv-xjf3-x35v)) (#10489) 2026-06-01 23:36:26 +02:00
Manuel 552c6dd754 fix: Server option routeAllowList is bypassable through batch sub-requests ([GHSA-p84r-h6rx-f2xr](https://github.com/parse-community/parse-server/security/advisories/GHSA-p84r-h6rx-f2xr)) (#10482) 2026-05-27 22:41:48 +02:00
Manuel 0ae0ed382b test: GraphQL endpoint is exempt from routeAllowList by design (#10480) 2026-05-27 00:36:20 +02:00
Manuel 155123ade9 fix: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj](https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj)) (#10467) 2026-05-18 17:04:56 +02:00
Manuel 56c159ec96 fix: Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm](https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm)) (#10463) 2026-05-17 15:11:10 +01:00
Manuel 9fee1a0708 feat: Add installation deviceToken deduplication options (#10451) 2026-04-30 23:11:39 +01:00
Manuel 725be0d602 fix: MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) (#10448) 2026-04-26 03:10:27 +01:00
Manuel f26700e39d feat: Add rawValues and rawFieldNames options for aggregation queries (#10438) 2026-04-17 09:12:18 +01:00
Yogendra Singh 60a58ec11a fix: Context mutations leak across requests in ParseServerRESTController (#10291) 2026-04-12 15:20:58 +01:00
Manuel fd31159859 fix: Facebook Standard Login missing app ID validation (#10429) 2026-04-12 01:16:11 +01:00
Manuel bf40004d25 feat: Add requestComplexity.subqueryLimit option to limit subquery results (#10420) 2026-04-10 16:49:34 +01:00
Manuel 18482e386c feat: Add requestComplexity.allowRegex option to disable $regex query operator (#10418) 2026-04-09 18:12:12 +01:00
Antoine Cormouls f208037b3b refactor: Replace uuid dependency with native UUID (#10416) 2026-04-08 14:17:24 +01:00
Manuel c0889c8575 fix: Master key does not bypass protectedFields on various endpoints (#10412) 2026-04-07 13:48:39 +01:00
Manuel 8a3db3b966 fix: Endpoints /login and /verifyPassword ignore _User protectedFields (#10409) 2026-04-07 13:01:11 +01:00
Manuel c136e2b7ab fix: Endpoint /upgradeToRevocableSession ignores _Session protectedFields (#10408) 2026-04-07 10:09:09 +01:00
Manuel d5075758f6 fix: Endpoint /sessions/me bypasses _Session protectedFields ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) (#10406) 2026-04-06 17:46:32 +01:00
Manuel 531b9ab6dd fix: Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) (#10398) 2026-04-05 17:48:57 +01:00
Manuel a3f36a2ddb feat: Add support for invoking Cloud Function with multipart/form-data protocol (#10395) 2026-04-04 17:46:51 +01:00
Manuel fc117efa4d feat: Add server option fileDownload to restrict file download (#10394) 2026-04-03 19:41:42 +01:00
Manuel 7d8b367e0b fix: Maintenance key IP mismatch silently downgrades to regular auth instead of rejecting (#10391) 2026-04-03 17:36:27 +01:00
Manuel f2d06e7b95 feat: Add route block with new server option routeAllowList (#10389) 2026-04-03 16:08:18 +01:00
Manuel dd7cc41a95 fix: File upload Content-Type override via extension mismatch ([GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc)) (#10383) 2026-04-02 02:19:26 +01:00
Manuel ead12bd1df fix: Session field guard bypass via falsy values for ACL and user fields (#10382) 2026-04-01 21:25:30 +01:00
Manuel 66350964c8 fix: Nested batch sub-requests cause unclear error (#10371) 2026-04-01 14:35:25 +01:00
Manuel a0b0c69fc4 fix: Streaming file download bypasses afterFind file trigger authorization ([GHSA-hpm8-9qx6-jvwv](https://github.com/parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv)) (#10361) 2026-03-31 00:17:57 +01:00
Manuel aea7596cd2 feat: Extend storage adapter interface to optionally return matchedCount and modifiedCount from DatabaseController.update with many: true (#10353) 2026-03-30 01:09:10 +01:00
Manuel d5f5128ade fix: Cloud Code trigger context vulnerable to prototype pollution (#10352) 2026-03-30 00:21:18 +01:00
Manuel f63fd1a3fe fix: LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) (#10350) 2026-03-29 19:36:52 +01:00
Manuel 63c37c49c7 fix: Batch login sub-request rate limit uses IP-based keying (#10349) 2026-03-29 16:08:36 +01:00
Manuel 90802969fc fix: Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) (#10347) 2026-03-29 04:55:39 +01:00