Manuel
|
2a9fdab367
|
fix: Validate session in middleware for non-GET requests to /sessions/me (#10213)
|
2026-03-15 18:51:40 +00:00 |
|
Manuel
|
386a989bd2
|
fix: Validate token type in PagesRouter to prevent type confusion errors (#10212)
|
2026-03-15 18:43:23 +00:00 |
|
Manuel
|
286373dddf
|
fix: Cloud function dispatch crashes server via prototype chain traversal ([GHSA-4263-jgmp-7pf4](https://github.com/parse-community/parse-server/security/advisories/GHSA-4263-jgmp-7pf4)) (#10210)
|
2026-03-15 17:13:30 +00:00 |
|
Manuel
|
df690463f8
|
fix: Validate body field types in request middleware (#10209)
|
2026-03-15 15:41:02 +00:00 |
|
Manuel
|
ad463d2e42
|
test: LiveQuery operator type confusion (GHSA-fjxm-vhvc-gcmj) (#10208)
|
2026-03-15 14:48:02 +00:00 |
|
Manuel
|
f403131cc5
|
refactor: Deprecate disabled default values for query complexity limits (#10207)
|
2026-03-15 04:10:21 +00:00 |
|
Manuel
|
ab8dd54d8b
|
fix: Revert accidental breaking default values for query complexity limits (#10205)
|
2026-03-15 03:33:22 +00:00 |
|
Manuel
|
f44e306147
|
fix: Server crash via deeply nested query condition operators ([GHSA-9xp9-j92r-p88v](https://github.com/parse-community/parse-server/security/advisories/GHSA-9xp9-j92r-p88v)) (#10202)
|
2026-03-15 02:54:49 +00:00 |
|
Manuel
|
b321423867
|
fix: Schema poisoning via prototype pollution in deep copy ([GHSA-9ccr-fpp6-78qf](https://github.com/parse-community/parse-server/security/advisories/GHSA-9ccr-fpp6-78qf)) (#10200)
|
2026-03-14 16:01:04 +01:00 |
|
Manuel
|
0ae0eeee52
|
fix: LiveQuery subscription with invalid regular expression crashes server ([GHSA-827p-g5x5-h86c](https://github.com/parse-community/parse-server/security/advisories/GHSA-827p-g5x5-h86c)) (#10197)
|
2026-03-14 14:23:27 +01:00 |
|
Manuel
|
7ccfb972d4
|
fix: Session creation endpoint allows overwriting server-generated session fields ([GHSA-5v7g-9h8f-8pgg](https://github.com/parse-community/parse-server/security/advisories/GHSA-5v7g-9h8f-8pgg)) (#10195)
|
2026-03-14 00:35:56 +01:00 |
|
Manuel
|
a944203b26
|
fix: Session token expiration unchecked on cache hit (#10194)
|
2026-03-13 23:47:51 +01:00 |
|
Manuel
|
4f53ab3cad
|
fix: Stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries ([GHSA-42ph-pf9q-cr72](https://github.com/parse-community/parse-server/security/advisories/GHSA-42ph-pf9q-cr72)) (#10191)
|
2026-03-13 21:34:02 +01:00 |
|
Manuel
|
3ffba757bf
|
fix: GraphQL WebSocket endpoint bypasses security middleware ([GHSA-p2x3-8689-cwpg](https://github.com/parse-community/parse-server/security/advisories/GHSA-p2x3-8689-cwpg)) (#10189)
|
2026-03-12 14:23:50 +00:00 |
|
Manuel
|
7f9f854be7
|
fix: OAuth2 adapter app ID validation sends wrong token to introspection endpoint ([GHSA-69xg-f649-w5g2](https://github.com/parse-community/parse-server/security/advisories/GHSA-69xg-f649-w5g2)) (#10187)
|
2026-03-11 23:48:06 +00:00 |
|
Manuel
|
0d0a5543b3
|
fix: Account takeover via operator injection in authentication data identifier ([GHSA-5fw2-8jcv-xh87](https://github.com/parse-community/parse-server/security/advisories/GHSA-5fw2-8jcv-xh87)) (#10185)
|
2026-03-11 18:07:34 +00:00 |
|
Manuel
|
6009bc15c8
|
fix: OAuth2 adapter shares mutable state across providers via singleton instance ([GHSA-2cjm-2gwv-m892](https://github.com/parse-community/parse-server/security/advisories/GHSA-2cjm-2gwv-m892)) (#10183)
|
2026-03-11 16:37:14 +00:00 |
|
Manuel
|
be281b1ed9
|
fix: SQL injection via query field name when using PostgreSQL ([GHSA-c442-97qw-j6c6](https://github.com/parse-community/parse-server/security/advisories/GHSA-c442-97qw-j6c6)) (#10181)
|
2026-03-11 14:39:21 +00:00 |
|
Manuel
|
b43b22467d
|
SQL injection via query field name when using PostgreSQL ([GHSA-c442-97qw-j6c6](https://github.com/parse-community/parse-server/security/advisories/GHSA-c442-97qw-j6c6)) (#10177)
|
2026-03-11 14:22:41 +00:00 |
|
Manuel
|
4d48847e99
|
fix: Protected fields bypass via LiveQuery subscription WHERE clause ([GHSA-j7mm-f4rv-6q6q](https://github.com/parse-community/parse-server/security/advisories/GHSA-j7mm-f4rv-6q6q)) (#10175)
|
2026-03-10 20:53:25 +00:00 |
|
Manuel
|
0744225caf
|
docs: Clarify user lockout when setting empty ACL (#10174)
|
2026-03-10 15:29:34 +00:00 |
|
Manuel
|
936abd4905
|
fix: User enumeration via email verification endpoint ([GHSA-w54v-hf9p-8856](https://github.com/parse-community/parse-server/security/advisories/GHSA-w54v-hf9p-8856)) (#10172)
|
2026-03-10 13:58:58 +00:00 |
|
Manuel
|
18abdd960b
|
fix: MFA recovery codes not consumed after use ([GHSA-4hf6-3x24-c9m8](https://github.com/parse-community/parse-server/security/advisories/GHSA-4hf6-3x24-c9m8)) (#10170)
|
2026-03-10 04:22:17 +00:00 |
|
Manuel
|
620844d00a
|
test: Verify prototype pollution via application ID is blocked by middleware (#10169)
|
2026-03-10 03:54:46 +00:00 |
|
Manuel
|
8f54c5437b
|
fix: Protected fields bypass via dot-notation in query and sort ([GHSA-r2m8-pxm9-9c4g](https://github.com/parse-community/parse-server/security/advisories/GHSA-r2m8-pxm9-9c4g)) (#10167)
|
2026-03-10 02:04:25 +00:00 |
|
Manuel
|
169d69257d
|
fix: SQL Injection via dot-notation sub-key name in Increment operation on PostgreSQL ([GHSA-gqpp-xgvh-9h7h](https://github.com/parse-community/parse-server/security/advisories/GHSA-gqpp-xgvh-9h7h)) (#10165)
|
2026-03-10 00:59:42 +00:00 |
|
Manuel
|
03287cf83b
|
fix: Stored XSS via file upload of HTML-renderable file types ([GHSA-v5hf-f4c3-m5rv](https://github.com/parse-community/parse-server/security/advisories/GHSA-v5hf-f4c3-m5rv)) (#10162)
|
2026-03-09 23:50:23 +00:00 |
|
Manuel
|
8f822826a4
|
fix: SQL injection via Increment operation on nested object field in PostgreSQL ([GHSA-q3vj-96h2-gwvg](https://github.com/parse-community/parse-server/security/advisories/GHSA-q3vj-96h2-gwvg)) (#10161)
|
2026-03-09 21:30:28 +00:00 |
|
Manuel
|
ea538a4ba3
|
fix: SQL injection via dot-notation field name in PostgreSQL ([GHSA-qpr4-jrj4-6f27](https://github.com/parse-community/parse-server/security/advisories/GHSA-qpr4-jrj4-6f27)) (#10159)
|
2026-03-09 20:27:56 +00:00 |
|
Manuel
|
28d11a33bc
|
feat: Add X-Content-Type-Options: nosniff header and customizable response headers for files via Parse.Cloud.afterFind(Parse.File) (#10158)
|
2026-03-09 19:12:29 +00:00 |
|
Manuel
|
416cfbcd73
|
fix: LiveQuery regexTimeout default value not applied (#10156)
|
2026-03-09 18:03:17 +00:00 |
|
Manuel
|
5bbca7b862
|
fix: LDAP injection via unsanitized user input in DN and group filter construction ([GHSA-7m6r-fhh7-r47c](https://github.com/parse-community/parse-server/security/advisories/GHSA-7m6r-fhh7-r47c)) (#10154)
|
2026-03-09 14:06:32 +00:00 |
|
Manuel
|
1de4e43ca2
|
fix: Classes _GraphQLConfig and _Audience master key bypass via generic class routes ([GHSA-7xg7-rqf6-pw6c](https://github.com/parse-community/parse-server/security/advisories/GHSA-7xg7-rqf6-pw6c)) (#10151)
|
2026-03-09 03:41:12 +00:00 |
|
Manuel
|
853bfe1bd3
|
fix: Concurrent signup with same authentication creates duplicate users (#10149)
|
2026-03-09 02:05:27 +00:00 |
|
Manuel
|
2766f4f7a2
|
fix: Rate limit bypass via batch request endpoint ([GHSA-775h-3xrc-c228](https://github.com/parse-community/parse-server/security/advisories/GHSA-775h-3xrc-c228)) (#10147)
|
2026-03-08 20:30:45 +00:00 |
|
Manuel
|
9cfd06e0d0
|
fix: Parse Server OAuth2 authentication adapter account takeover via identity spoofing ([GHSA-fr88-w35c-r596](https://github.com/parse-community/parse-server/security/advisories/GHSA-fr88-w35c-r596)) (#10145)
|
2026-03-08 18:27:06 +00:00 |
|
Manuel
|
70b7b070e1
|
fix: Parse Server session token exfiltration via redirectClassNameForKey query parameter ([GHSA-6r2j-cxgf-495f](https://github.com/parse-community/parse-server/security/advisories/GHSA-6r2j-cxgf-495f)) (#10143)
|
2026-03-08 17:22:36 +00:00 |
|
Manuel
|
22faa08a7b
|
fix: Parse Server role escalation and CLP bypass via direct `_Join table write ([GHSA-5f92-jrq3-28rc](https://github.com/parse-community/parse-server/security/advisories/GHSA-5f92-jrq3-28rc)) (#10141)
|
2026-03-08 16:26:41 +00:00 |
|
Manuel
|
be1d65dac5
|
fix: Protected fields bypass via logical query operators ([GHSA-72hp-qff8-4pvv](https://github.com/parse-community/parse-server/security/advisories/GHSA-72hp-qff8-4pvv)) (#10140)
|
2026-03-08 15:25:22 +00:00 |
|
Manuel
|
78ef1a175d
|
fix: Missing audience validation in Keycloak authentication adapter ([GHSA-48mh-j4p5-7j9v](https://github.com/parse-community/parse-server/security/advisories/GHSA-48mh-j4p5-7j9v)) (#10137)
|
2026-03-08 03:50:10 +00:00 |
|
Manuel
|
93b784d21a
|
fix: Stored cross-site scripting (XSS) via SVG file upload ([GHSA-hcj7-6gxh-24ww](https://github.com/parse-community/parse-server/security/advisories/GHSA-hcj7-6gxh-24ww)) (#10136)
|
2026-03-08 02:04:59 +00:00 |
|
Manuel
|
98188d92c0
|
fix: Bypass of class-level permissions in LiveQuery ([GHSA-7ch5-98q2-7289](https://github.com/parse-community/parse-server/security/advisories/GHSA-7ch5-98q2-7289)) (#10133)
|
2026-03-08 01:15:08 +00:00 |
|
Manuel
|
0a86d5cb91
|
ci: Performance benchmark job not failing on regression (#10132)
|
2026-03-07 23:46:18 +00:00 |
|
Manuel
|
0ae9c25bc1
|
fix: Denial-of-service via unbounded query complexity in REST and GraphQL API ([GHSA-cmj3-wx7h-ffvg](https://github.com/parse-community/parse-server/security/advisories/GHSA-cmj3-wx7h-ffvg)) (#10130)
|
2026-03-07 23:40:45 +00:00 |
|
Manuel
|
b2f23172e4
|
fix: NoSQL injection via token type in password reset and email verification endpoints ([GHSA-vgjh-hmwf-c588](https://github.com/parse-community/parse-server/security/advisories/GHSA-vgjh-hmwf-c588)) (#10128)
|
2026-03-07 19:16:38 +00:00 |
|
Manuel
|
1688c77a5c
|
build: Release (#10127)
|
2026-03-07 18:19:17 +00:00 |
|
Manuel
|
0e06b93d83
|
ci: Performance benchmark job not failing on regression (#10126)
|
2026-03-07 17:42:11 +00:00 |
|
Manuel
|
560e6e77c7
|
fix: Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution ([GHSA-5j86-7r7m-p8h6](https://github.com/parse-community/parse-server/security/advisories/GHSA-5j86-7r7m-p8h6)) (#10125)
|
2026-03-07 17:38:13 +00:00 |
|
Manuel
|
4a44247a64
|
fix: Denylist requestKeywordDenylist keyword scan bypass through nested object placement ([GHSA-q342-9w2p-57fp](https://github.com/parse-community/parse-server/security/advisories/GHSA-q342-9w2p-57fp)) (#10123)
|
2026-03-07 16:40:34 +00:00 |
|
Manuel
|
7bdc4d393b
|
build: Release (#10121)
|
2026-03-07 02:42:07 +00:00 |
|
Manuel
|
5e113c2128
|
fix: Regular Expression Denial of Service (ReDoS) via $regex query in LiveQuery ([GHSA-mf3j-86qx-cq5j](https://github.com/parse-community/parse-server/security/advisories/GHSA-mf3j-86qx-cq5j)) (#10118)
|
2026-03-07 02:14:37 +00:00 |
|
Manuel
|
22d707240e
|
ci: Add performance benchmark for regex in Parse.Query (#10117)
|
2026-03-06 21:33:26 +00:00 |
|
Manuel
|
d54d800f59
|
feat: Deprecate GraphQL Playground that exposes master key in HTTP response (#10112)
|
2026-03-06 18:28:23 +00:00 |
|
Manuel
|
cbff6b42a0
|
feat: Add server option readOnlyMasterKeyIps to restrict readOnlyMasterKey by IP (#10115)
|
2026-03-06 18:12:17 +00:00 |
|
Manuel
|
9f8d3f3d55
|
fix: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters ([GHSA-x6fw-778m-wr9v](https://github.com/parse-community/parse-server/security/advisories/GHSA-x6fw-778m-wr9v)) (#10113)
|
2026-03-06 05:12:13 +00:00 |
|
Manuel
|
61261a5aa1
|
fix: GraphQL __type introspection bypass via inline fragments when public introspection is disabled ([GHSA-q5q9-2rhp-33qw](https://github.com/parse-community/parse-server/security/advisories/GHSA-q5q9-2rhp-33qw)) (#10111)
|
2026-03-06 02:25:34 +00:00 |
|
Manuel
|
c6b747036b
|
refactor: Add poisoned object ID guard to legacy session auth path (#10109)
|
2026-03-06 01:48:33 +00:00 |
|
Manuel
|
72e7707ac1
|
fix: File metadata endpoint bypasses beforeFind / afterFind trigger authorization ([GHSA-hwx8-q9cg-mqmc](https://github.com/parse-community/parse-server/security/advisories/GHSA-hwx8-q9cg-mqmc)) (#10106)
|
2026-03-06 01:05:08 +00:00 |
|
Manuel
|
e772543ad8
|
fix: PagesRouter path traversal allows reading files outside configured pages directory ([GHSA-hm3f-q6rw-m6wh](https://github.com/parse-community/parse-server/security/advisories/GHSA-hm3f-q6rw-m6wh)) (#10104)
|
2026-03-05 23:48:58 +00:00 |
|
Manuel
|
2ae5db1425
|
feat: Add security check for server option mountPlayground for GraphQL development (#10103)
|
2026-03-05 23:18:07 +00:00 |
|
Manuel
|
9792d24b96
|
fix: Malformed $regex query leaks database error details in API response ([GHSA-9cp7-3q5w-j92g](https://github.com/parse-community/parse-server/security/advisories/GHSA-9cp7-3q5w-j92g)) (#10101)
|
2026-03-05 20:46:05 +00:00 |
|
Manuel
|
2c48751c6d
|
feat: Allow to identify readOnlyMasterKey invocation of Cloud Function via request.isReadOnly (#10100)
|
2026-03-05 03:39:57 +00:00 |
|
Manuel
|
bc20945fc7
|
fix: Endpoint /loginAs allows readOnlyMasterKey to gain full read and write access as any user ([GHSA-79wj-8rqv-jvp5](https://github.com/parse-community/parse-server/security/advisories/GHSA-79wj-8rqv-jvp5)) (#10098)
|
2026-03-05 02:28:51 +00:00 |
|
Manuel
|
036365af6d
|
fix: File creation and deletion bypasses readOnlyMasterKey write restriction ([GHSA-xfh7-phr7-gr2x](https://github.com/parse-community/parse-server/security/advisories/GHSA-xfh7-phr7-gr2x)) (#10095)
|
2026-03-05 01:45:53 +00:00 |
|
Manuel
|
421fe10723
|
ci: Add GC memory pressure performance test (#10094)
|
2026-03-05 00:51:03 +00:00 |
|
Manuel
|
3d8807b4ec
|
feat: Add Parse.File option maxUploadSize to override the Parse Server option maxUploadSize per file upload (#10093)
|
2026-03-04 19:50:09 +00:00 |
|
Manuel
|
ca666b02fc
|
feat: Add support for Parse.File.setDirectory, setMetadata, setTags with stream-based file upload (#10092)
|
2026-03-04 17:22:26 +00:00 |
|
Manuel
|
38adef7457
|
build: Release (#10090)
|
2026-03-04 00:45:20 +00:00 |
|
Manuel
|
9a3dd4d2d5
|
fix: Cloud Hooks and Cloud Jobs bypass readOnlyMasterKey write restriction ([GHSA-vc89-5g3r-cmhh](https://github.com/parse-community/parse-server/security/advisories/GHSA-vc89-5g3r-cmhh)) (#10088)
|
2026-03-04 00:15:38 +00:00 |
|
Manuel
|
bebf2fd62b
|
perf: Upgrade to mongodb 7.1.0 (#10087)
|
2026-03-03 13:53:52 +00:00 |
|
Manuel
|
8f1739788d
|
fix: MongoDB default batch size changed from 1000 to 100 without announcement (#10085)
|
2026-03-03 00:39:56 +00:00 |
|
Manuel
|
85702b2a50
|
build: Release (#10084)
|
2026-03-01 20:16:51 +00:00 |
|
Manuel
|
aca4dadc36
|
refactor: Add missing entry in DEPRECATIONS.md (#10079)
|
2026-02-27 18:55:59 +00:00 |
|
Manuel
|
c92660bd9a
|
fix: PagesRouter header parameters are not URL-encoded to support non-ASCII characters in app name (#10078)
|
2026-02-27 18:54:19 +00:00 |
|
Manuel
|
17d987c95a
|
feat: Add support for Parse.File.setDirectory() with master key to save file in directory (#10076)
|
2026-02-26 00:32:29 +00:00 |
|
Manuel
|
dbc31c43f0
|
build: Release (#10075)
|
2026-02-25 01:19:51 +00:00 |
|
Manuel
|
9d5942d50e
|
fix: JWT Algorithm Confusion in Google Auth Adapter ([GHSA-4q3h-vp4r-prv2](https://github.com/parse-community/parse-server/security/advisories/GHSA-4q3h-vp4r-prv2)) (#10072)
|
2026-02-23 22:01:47 +00:00 |
|
Manuel
|
00b3b7297d
|
fix: Remove obsolete Parse Server option pages.enableRouter (#10070)
|
2026-02-21 17:31:04 +00:00 |
|
Manuel
|
02a277f1e9
|
fix: Type error in docs creation (#10069)
|
2026-02-21 16:08:50 +00:00 |
|
Manuel
|
ec05f17b51
|
build: Release (#10068)
|
2026-02-21 15:32:03 +00:00 |
|
Manuel
|
f0feb48d0f
|
feat: Add support for streaming file upload via Buffer, Readable, ReadableStream (#10065)
|
2026-02-21 03:31:16 +00:00 |
|
Manuel
|
1a2521d930
|
fix: Incorrect dependency chain of Parse uses browser build instead of Node build (#10067)
|
2026-02-21 01:20:12 +00:00 |
|
Manuel
|
8b5a14ecaf
|
feat: Upgrade to parse 8.2.0, @parse/push-adapter 8.3.0 (#10066)
|
2026-02-20 20:00:21 +00:00 |
|
Manuel
|
44a5bb105e
|
fix: Parse.Query.select('authData') for _User class doesn't return auth data (#10055)
|
2026-02-12 20:45:41 +00:00 |
|
Manuel
|
b6b6327552
|
fix: Unlinking auth provider triggers auth data validation (#10045)
|
2026-02-12 02:28:48 +00:00 |
|
Manuel
|
4c9c9489f0
|
feat: Add Parse.File.url validation with config fileUpload.allowedFileUrlDomains against SSRF attacks (#10044)
|
2026-02-07 17:03:39 +00:00 |
|
Manuel
|
9e07ca6d3b
|
refactor: Bump prettier from 2.0.5 to 3.8.1 (#10042)
|
2026-02-07 01:11:09 +00:00 |
|
Manuel
|
a4265bb124
|
fix: Default HTML pages for password reset, email verification not found (#10041)
|
2026-02-06 16:30:13 +00:00 |
|
Manuel
|
e29910764d
|
fix: Default HTML pages for password reset, email verification not found (#10034)
|
2026-02-06 01:42:54 +00:00 |
|
Manuel
|
88b6977333
|
build: Release (#10036)
|
2026-02-05 13:09:31 +00:00 |
|
Manuel
|
c015864293
|
docs: Simplify PR template (#10026)
|
2026-01-27 18:07:02 +01:00 |
|
Manuel
|
9833fdb111
|
feat: Upgrade to parse 8.0.3 and @parse/push-adapter 8.2.0 (#10021)
|
2026-01-27 18:01:57 +01:00 |
|
Manuel
|
1d3336d128
|
fix: MongoDB timeout errors unhandled and potentially revealing internal data (#10020)
|
2026-01-25 00:15:01 +01:00 |
|
Manuel
|
69da47284c
|
docs: Add frozen LTS branch info to CONTRIBUTING guide (#10008)
|
2026-01-16 05:05:27 +01:00 |
|
Manuel
|
519d798781
|
build: Release (#9990)
|
2025-12-16 02:34:01 +01:00 |
|
Manuel
|
fbcc938b5a
|
fix: Server-Side Request Forgery (SSRF) in Instagram auth adapter [GHSA-3f5f-xgrj-97pf](https://github.com/parse-community/parse-server/security/advisories/GHSA-3f5f-xgrj-97pf) (#9988)
|
2025-12-16 02:24:37 +01:00 |
|
Manuel
|
8c4d67a0fe
|
build: Release (#9987)
|
2025-12-14 16:48:45 +01:00 |
|
Manuel
|
3074eb70f5
|
fix: Cross-Site Scripting (XSS) via HTML pages for password reset and email verification [GHSA-jhgf-2h8h-ggxv](https://github.com/parse-community/parse-server/security/advisories/GHSA-jhgf-2h8h-ggxv) (#9985)
|
2025-12-14 15:44:04 +01:00 |
|
Manuel
|
3b38dff6ca
|
docs: Clarify wording in DEPRECATIONS table (#9983)
|
2025-12-14 01:36:47 +01:00 |
|
Manuel
|
247c14c5db
|
build: Release (#9984)
|
2025-12-14 01:33:36 +01:00 |
|