Commit Graph
100 Commits
Author SHA1 Message Date
Manuel 2a9fdab367 fix: Validate session in middleware for non-GET requests to /sessions/me (#10213) 2026-03-15 18:51:40 +00:00
Manuel 386a989bd2 fix: Validate token type in PagesRouter to prevent type confusion errors (#10212) 2026-03-15 18:43:23 +00:00
Manuel 286373dddf fix: Cloud function dispatch crashes server via prototype chain traversal ([GHSA-4263-jgmp-7pf4](https://github.com/parse-community/parse-server/security/advisories/GHSA-4263-jgmp-7pf4)) (#10210) 2026-03-15 17:13:30 +00:00
Manuel df690463f8 fix: Validate body field types in request middleware (#10209) 2026-03-15 15:41:02 +00:00
Manuel ad463d2e42 test: LiveQuery operator type confusion (GHSA-fjxm-vhvc-gcmj) (#10208) 2026-03-15 14:48:02 +00:00
Manuel f403131cc5 refactor: Deprecate disabled default values for query complexity limits (#10207) 2026-03-15 04:10:21 +00:00
Manuel ab8dd54d8b fix: Revert accidental breaking default values for query complexity limits (#10205) 2026-03-15 03:33:22 +00:00
Manuel f44e306147 fix: Server crash via deeply nested query condition operators ([GHSA-9xp9-j92r-p88v](https://github.com/parse-community/parse-server/security/advisories/GHSA-9xp9-j92r-p88v)) (#10202) 2026-03-15 02:54:49 +00:00
Manuel b321423867 fix: Schema poisoning via prototype pollution in deep copy ([GHSA-9ccr-fpp6-78qf](https://github.com/parse-community/parse-server/security/advisories/GHSA-9ccr-fpp6-78qf)) (#10200) 2026-03-14 16:01:04 +01:00
Manuel 0ae0eeee52 fix: LiveQuery subscription with invalid regular expression crashes server ([GHSA-827p-g5x5-h86c](https://github.com/parse-community/parse-server/security/advisories/GHSA-827p-g5x5-h86c)) (#10197) 2026-03-14 14:23:27 +01:00
Manuel 7ccfb972d4 fix: Session creation endpoint allows overwriting server-generated session fields ([GHSA-5v7g-9h8f-8pgg](https://github.com/parse-community/parse-server/security/advisories/GHSA-5v7g-9h8f-8pgg)) (#10195) 2026-03-14 00:35:56 +01:00
Manuel a944203b26 fix: Session token expiration unchecked on cache hit (#10194) 2026-03-13 23:47:51 +01:00
Manuel 4f53ab3cad fix: Stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries ([GHSA-42ph-pf9q-cr72](https://github.com/parse-community/parse-server/security/advisories/GHSA-42ph-pf9q-cr72)) (#10191) 2026-03-13 21:34:02 +01:00
Manuel 3ffba757bf fix: GraphQL WebSocket endpoint bypasses security middleware ([GHSA-p2x3-8689-cwpg](https://github.com/parse-community/parse-server/security/advisories/GHSA-p2x3-8689-cwpg)) (#10189) 2026-03-12 14:23:50 +00:00
Manuel 7f9f854be7 fix: OAuth2 adapter app ID validation sends wrong token to introspection endpoint ([GHSA-69xg-f649-w5g2](https://github.com/parse-community/parse-server/security/advisories/GHSA-69xg-f649-w5g2)) (#10187) 2026-03-11 23:48:06 +00:00
Manuel 0d0a5543b3 fix: Account takeover via operator injection in authentication data identifier ([GHSA-5fw2-8jcv-xh87](https://github.com/parse-community/parse-server/security/advisories/GHSA-5fw2-8jcv-xh87)) (#10185) 2026-03-11 18:07:34 +00:00
Manuel 6009bc15c8 fix: OAuth2 adapter shares mutable state across providers via singleton instance ([GHSA-2cjm-2gwv-m892](https://github.com/parse-community/parse-server/security/advisories/GHSA-2cjm-2gwv-m892)) (#10183) 2026-03-11 16:37:14 +00:00
Manuel be281b1ed9 fix: SQL injection via query field name when using PostgreSQL ([GHSA-c442-97qw-j6c6](https://github.com/parse-community/parse-server/security/advisories/GHSA-c442-97qw-j6c6)) (#10181) 2026-03-11 14:39:21 +00:00
Manuel b43b22467d SQL injection via query field name when using PostgreSQL ([GHSA-c442-97qw-j6c6](https://github.com/parse-community/parse-server/security/advisories/GHSA-c442-97qw-j6c6)) (#10177) 2026-03-11 14:22:41 +00:00
Manuel 4d48847e99 fix: Protected fields bypass via LiveQuery subscription WHERE clause ([GHSA-j7mm-f4rv-6q6q](https://github.com/parse-community/parse-server/security/advisories/GHSA-j7mm-f4rv-6q6q)) (#10175) 2026-03-10 20:53:25 +00:00
Manuel 0744225caf docs: Clarify user lockout when setting empty ACL (#10174) 2026-03-10 15:29:34 +00:00
Manuel 936abd4905 fix: User enumeration via email verification endpoint ([GHSA-w54v-hf9p-8856](https://github.com/parse-community/parse-server/security/advisories/GHSA-w54v-hf9p-8856)) (#10172) 2026-03-10 13:58:58 +00:00
Manuel 18abdd960b fix: MFA recovery codes not consumed after use ([GHSA-4hf6-3x24-c9m8](https://github.com/parse-community/parse-server/security/advisories/GHSA-4hf6-3x24-c9m8)) (#10170) 2026-03-10 04:22:17 +00:00
Manuel 620844d00a test: Verify prototype pollution via application ID is blocked by middleware (#10169) 2026-03-10 03:54:46 +00:00
Manuel 8f54c5437b fix: Protected fields bypass via dot-notation in query and sort ([GHSA-r2m8-pxm9-9c4g](https://github.com/parse-community/parse-server/security/advisories/GHSA-r2m8-pxm9-9c4g)) (#10167) 2026-03-10 02:04:25 +00:00
Manuel 169d69257d fix: SQL Injection via dot-notation sub-key name in Increment operation on PostgreSQL ([GHSA-gqpp-xgvh-9h7h](https://github.com/parse-community/parse-server/security/advisories/GHSA-gqpp-xgvh-9h7h)) (#10165) 2026-03-10 00:59:42 +00:00
Manuel 03287cf83b fix: Stored XSS via file upload of HTML-renderable file types ([GHSA-v5hf-f4c3-m5rv](https://github.com/parse-community/parse-server/security/advisories/GHSA-v5hf-f4c3-m5rv)) (#10162) 2026-03-09 23:50:23 +00:00
Manuel 8f822826a4 fix: SQL injection via Increment operation on nested object field in PostgreSQL ([GHSA-q3vj-96h2-gwvg](https://github.com/parse-community/parse-server/security/advisories/GHSA-q3vj-96h2-gwvg)) (#10161) 2026-03-09 21:30:28 +00:00
Manuel ea538a4ba3 fix: SQL injection via dot-notation field name in PostgreSQL ([GHSA-qpr4-jrj4-6f27](https://github.com/parse-community/parse-server/security/advisories/GHSA-qpr4-jrj4-6f27)) (#10159) 2026-03-09 20:27:56 +00:00
Manuel 28d11a33bc feat: Add X-Content-Type-Options: nosniff header and customizable response headers for files via Parse.Cloud.afterFind(Parse.File) (#10158) 2026-03-09 19:12:29 +00:00
Manuel 416cfbcd73 fix: LiveQuery regexTimeout default value not applied (#10156) 2026-03-09 18:03:17 +00:00
Manuel 5bbca7b862 fix: LDAP injection via unsanitized user input in DN and group filter construction ([GHSA-7m6r-fhh7-r47c](https://github.com/parse-community/parse-server/security/advisories/GHSA-7m6r-fhh7-r47c)) (#10154) 2026-03-09 14:06:32 +00:00
Manuel 1de4e43ca2 fix: Classes _GraphQLConfig and _Audience master key bypass via generic class routes ([GHSA-7xg7-rqf6-pw6c](https://github.com/parse-community/parse-server/security/advisories/GHSA-7xg7-rqf6-pw6c)) (#10151) 2026-03-09 03:41:12 +00:00
Manuel 853bfe1bd3 fix: Concurrent signup with same authentication creates duplicate users (#10149) 2026-03-09 02:05:27 +00:00
Manuel 2766f4f7a2 fix: Rate limit bypass via batch request endpoint ([GHSA-775h-3xrc-c228](https://github.com/parse-community/parse-server/security/advisories/GHSA-775h-3xrc-c228)) (#10147) 2026-03-08 20:30:45 +00:00
Manuel 9cfd06e0d0 fix: Parse Server OAuth2 authentication adapter account takeover via identity spoofing ([GHSA-fr88-w35c-r596](https://github.com/parse-community/parse-server/security/advisories/GHSA-fr88-w35c-r596)) (#10145) 2026-03-08 18:27:06 +00:00
Manuel 70b7b070e1 fix: Parse Server session token exfiltration via redirectClassNameForKey query parameter ([GHSA-6r2j-cxgf-495f](https://github.com/parse-community/parse-server/security/advisories/GHSA-6r2j-cxgf-495f)) (#10143) 2026-03-08 17:22:36 +00:00
Manuel 22faa08a7b fix: Parse Server role escalation and CLP bypass via direct `_Join table write ([GHSA-5f92-jrq3-28rc](https://github.com/parse-community/parse-server/security/advisories/GHSA-5f92-jrq3-28rc)) (#10141) 2026-03-08 16:26:41 +00:00
Manuel be1d65dac5 fix: Protected fields bypass via logical query operators ([GHSA-72hp-qff8-4pvv](https://github.com/parse-community/parse-server/security/advisories/GHSA-72hp-qff8-4pvv)) (#10140) 2026-03-08 15:25:22 +00:00
Manuel 78ef1a175d fix: Missing audience validation in Keycloak authentication adapter ([GHSA-48mh-j4p5-7j9v](https://github.com/parse-community/parse-server/security/advisories/GHSA-48mh-j4p5-7j9v)) (#10137) 2026-03-08 03:50:10 +00:00
Manuel 93b784d21a fix: Stored cross-site scripting (XSS) via SVG file upload ([GHSA-hcj7-6gxh-24ww](https://github.com/parse-community/parse-server/security/advisories/GHSA-hcj7-6gxh-24ww)) (#10136) 2026-03-08 02:04:59 +00:00
Manuel 98188d92c0 fix: Bypass of class-level permissions in LiveQuery ([GHSA-7ch5-98q2-7289](https://github.com/parse-community/parse-server/security/advisories/GHSA-7ch5-98q2-7289)) (#10133) 2026-03-08 01:15:08 +00:00
Manuel 0a86d5cb91 ci: Performance benchmark job not failing on regression (#10132) 2026-03-07 23:46:18 +00:00
Manuel 0ae9c25bc1 fix: Denial-of-service via unbounded query complexity in REST and GraphQL API ([GHSA-cmj3-wx7h-ffvg](https://github.com/parse-community/parse-server/security/advisories/GHSA-cmj3-wx7h-ffvg)) (#10130) 2026-03-07 23:40:45 +00:00
Manuel b2f23172e4 fix: NoSQL injection via token type in password reset and email verification endpoints ([GHSA-vgjh-hmwf-c588](https://github.com/parse-community/parse-server/security/advisories/GHSA-vgjh-hmwf-c588)) (#10128) 2026-03-07 19:16:38 +00:00
Manuel 1688c77a5c build: Release (#10127) 2026-03-07 18:19:17 +00:00
Manuel 0e06b93d83 ci: Performance benchmark job not failing on regression (#10126) 2026-03-07 17:42:11 +00:00
Manuel 560e6e77c7 fix: Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution ([GHSA-5j86-7r7m-p8h6](https://github.com/parse-community/parse-server/security/advisories/GHSA-5j86-7r7m-p8h6)) (#10125) 2026-03-07 17:38:13 +00:00
Manuel 4a44247a64 fix: Denylist requestKeywordDenylist keyword scan bypass through nested object placement ([GHSA-q342-9w2p-57fp](https://github.com/parse-community/parse-server/security/advisories/GHSA-q342-9w2p-57fp)) (#10123) 2026-03-07 16:40:34 +00:00
Manuel 7bdc4d393b build: Release (#10121) 2026-03-07 02:42:07 +00:00
Manuel 5e113c2128 fix: Regular Expression Denial of Service (ReDoS) via $regex query in LiveQuery ([GHSA-mf3j-86qx-cq5j](https://github.com/parse-community/parse-server/security/advisories/GHSA-mf3j-86qx-cq5j)) (#10118) 2026-03-07 02:14:37 +00:00
Manuel 22d707240e ci: Add performance benchmark for regex in Parse.Query (#10117) 2026-03-06 21:33:26 +00:00
Manuel d54d800f59 feat: Deprecate GraphQL Playground that exposes master key in HTTP response (#10112) 2026-03-06 18:28:23 +00:00
Manuel cbff6b42a0 feat: Add server option readOnlyMasterKeyIps to restrict readOnlyMasterKey by IP (#10115) 2026-03-06 18:12:17 +00:00
Manuel 9f8d3f3d55 fix: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters ([GHSA-x6fw-778m-wr9v](https://github.com/parse-community/parse-server/security/advisories/GHSA-x6fw-778m-wr9v)) (#10113) 2026-03-06 05:12:13 +00:00
Manuel 61261a5aa1 fix: GraphQL __type introspection bypass via inline fragments when public introspection is disabled ([GHSA-q5q9-2rhp-33qw](https://github.com/parse-community/parse-server/security/advisories/GHSA-q5q9-2rhp-33qw)) (#10111) 2026-03-06 02:25:34 +00:00
Manuel c6b747036b refactor: Add poisoned object ID guard to legacy session auth path (#10109) 2026-03-06 01:48:33 +00:00
Manuel 72e7707ac1 fix: File metadata endpoint bypasses beforeFind / afterFind trigger authorization ([GHSA-hwx8-q9cg-mqmc](https://github.com/parse-community/parse-server/security/advisories/GHSA-hwx8-q9cg-mqmc)) (#10106) 2026-03-06 01:05:08 +00:00
Manuel e772543ad8 fix: PagesRouter path traversal allows reading files outside configured pages directory ([GHSA-hm3f-q6rw-m6wh](https://github.com/parse-community/parse-server/security/advisories/GHSA-hm3f-q6rw-m6wh)) (#10104) 2026-03-05 23:48:58 +00:00
Manuel 2ae5db1425 feat: Add security check for server option mountPlayground for GraphQL development (#10103) 2026-03-05 23:18:07 +00:00
Manuel 9792d24b96 fix: Malformed $regex query leaks database error details in API response ([GHSA-9cp7-3q5w-j92g](https://github.com/parse-community/parse-server/security/advisories/GHSA-9cp7-3q5w-j92g)) (#10101) 2026-03-05 20:46:05 +00:00
Manuel 2c48751c6d feat: Allow to identify readOnlyMasterKey invocation of Cloud Function via request.isReadOnly (#10100) 2026-03-05 03:39:57 +00:00
Manuel bc20945fc7 fix: Endpoint /loginAs allows readOnlyMasterKey to gain full read and write access as any user ([GHSA-79wj-8rqv-jvp5](https://github.com/parse-community/parse-server/security/advisories/GHSA-79wj-8rqv-jvp5)) (#10098) 2026-03-05 02:28:51 +00:00
Manuel 036365af6d fix: File creation and deletion bypasses readOnlyMasterKey write restriction ([GHSA-xfh7-phr7-gr2x](https://github.com/parse-community/parse-server/security/advisories/GHSA-xfh7-phr7-gr2x)) (#10095) 2026-03-05 01:45:53 +00:00
Manuel 421fe10723 ci: Add GC memory pressure performance test (#10094) 2026-03-05 00:51:03 +00:00
Manuel 3d8807b4ec feat: Add Parse.File option maxUploadSize to override the Parse Server option maxUploadSize per file upload (#10093) 2026-03-04 19:50:09 +00:00
Manuel ca666b02fc feat: Add support for Parse.File.setDirectory, setMetadata, setTags with stream-based file upload (#10092) 2026-03-04 17:22:26 +00:00
Manuel 38adef7457 build: Release (#10090) 2026-03-04 00:45:20 +00:00
Manuel 9a3dd4d2d5 fix: Cloud Hooks and Cloud Jobs bypass readOnlyMasterKey write restriction ([GHSA-vc89-5g3r-cmhh](https://github.com/parse-community/parse-server/security/advisories/GHSA-vc89-5g3r-cmhh)) (#10088) 2026-03-04 00:15:38 +00:00
Manuel bebf2fd62b perf: Upgrade to mongodb 7.1.0 (#10087) 2026-03-03 13:53:52 +00:00
Manuel 8f1739788d fix: MongoDB default batch size changed from 1000 to 100 without announcement (#10085) 2026-03-03 00:39:56 +00:00
Manuel 85702b2a50 build: Release (#10084) 2026-03-01 20:16:51 +00:00
Manuel aca4dadc36 refactor: Add missing entry in DEPRECATIONS.md (#10079) 2026-02-27 18:55:59 +00:00
Manuel c92660bd9a fix: PagesRouter header parameters are not URL-encoded to support non-ASCII characters in app name (#10078) 2026-02-27 18:54:19 +00:00
Manuel 17d987c95a feat: Add support for Parse.File.setDirectory() with master key to save file in directory (#10076) 2026-02-26 00:32:29 +00:00
Manuel dbc31c43f0 build: Release (#10075) 2026-02-25 01:19:51 +00:00
Manuel 9d5942d50e fix: JWT Algorithm Confusion in Google Auth Adapter ([GHSA-4q3h-vp4r-prv2](https://github.com/parse-community/parse-server/security/advisories/GHSA-4q3h-vp4r-prv2)) (#10072) 2026-02-23 22:01:47 +00:00
Manuel 00b3b7297d fix: Remove obsolete Parse Server option pages.enableRouter (#10070) 2026-02-21 17:31:04 +00:00
Manuel 02a277f1e9 fix: Type error in docs creation (#10069) 2026-02-21 16:08:50 +00:00
Manuel ec05f17b51 build: Release (#10068) 2026-02-21 15:32:03 +00:00
Manuel f0feb48d0f feat: Add support for streaming file upload via Buffer, Readable, ReadableStream (#10065) 2026-02-21 03:31:16 +00:00
Manuel 1a2521d930 fix: Incorrect dependency chain of Parse uses browser build instead of Node build (#10067) 2026-02-21 01:20:12 +00:00
Manuel 8b5a14ecaf feat: Upgrade to parse 8.2.0, @parse/push-adapter 8.3.0 (#10066) 2026-02-20 20:00:21 +00:00
Manuel 44a5bb105e fix: Parse.Query.select('authData') for _User class doesn't return auth data (#10055) 2026-02-12 20:45:41 +00:00
Manuel b6b6327552 fix: Unlinking auth provider triggers auth data validation (#10045) 2026-02-12 02:28:48 +00:00
Manuel 4c9c9489f0 feat: Add Parse.File.url validation with config fileUpload.allowedFileUrlDomains against SSRF attacks (#10044) 2026-02-07 17:03:39 +00:00
Manuel 9e07ca6d3b refactor: Bump prettier from 2.0.5 to 3.8.1 (#10042) 2026-02-07 01:11:09 +00:00
Manuel a4265bb124 fix: Default HTML pages for password reset, email verification not found (#10041) 2026-02-06 16:30:13 +00:00
Manuel e29910764d fix: Default HTML pages for password reset, email verification not found (#10034) 2026-02-06 01:42:54 +00:00
Manuel 88b6977333 build: Release (#10036) 2026-02-05 13:09:31 +00:00
Manuel c015864293 docs: Simplify PR template (#10026) 2026-01-27 18:07:02 +01:00
Manuel 9833fdb111 feat: Upgrade to parse 8.0.3 and @parse/push-adapter 8.2.0 (#10021) 2026-01-27 18:01:57 +01:00
Manuel 1d3336d128 fix: MongoDB timeout errors unhandled and potentially revealing internal data (#10020) 2026-01-25 00:15:01 +01:00
Manuel 69da47284c docs: Add frozen LTS branch info to CONTRIBUTING guide (#10008) 2026-01-16 05:05:27 +01:00
Manuel 519d798781 build: Release (#9990) 2025-12-16 02:34:01 +01:00
Manuel fbcc938b5a fix: Server-Side Request Forgery (SSRF) in Instagram auth adapter [GHSA-3f5f-xgrj-97pf](https://github.com/parse-community/parse-server/security/advisories/GHSA-3f5f-xgrj-97pf) (#9988) 2025-12-16 02:24:37 +01:00
Manuel 8c4d67a0fe build: Release (#9987) 2025-12-14 16:48:45 +01:00
Manuel 3074eb70f5 fix: Cross-Site Scripting (XSS) via HTML pages for password reset and email verification [GHSA-jhgf-2h8h-ggxv](https://github.com/parse-community/parse-server/security/advisories/GHSA-jhgf-2h8h-ggxv) (#9985) 2025-12-14 15:44:04 +01:00
Manuel 3b38dff6ca docs: Clarify wording in DEPRECATIONS table (#9983) 2025-12-14 01:36:47 +01:00
Manuel 247c14c5db build: Release (#9984) 2025-12-14 01:33:36 +01:00