Commit Graph
5205 Commits
Author SHA1 Message Date
semantic-release-bot dbd4281744 chore(release): 8.6.85 [skip ci]
## [8.6.85](https://github.com/parse-community/parse-server/compare/8.6.84...8.6.85) (2026-07-08)

### Bug Fixes

* GraphQL variable-coercion suggestions disclose schema to unauthenticated callers ([GHSA-9g8f-h8f3-hjcm](https://github.com/parse-community/parse-server/security/advisories/GHSA-9g8f-h8f3-hjcm)) ([#10564](https://github.com/parse-community/parse-server/issues/10564)) ([2728fcb](https://github.com/parse-community/parse-server/commit/2728fcbabcd8462e92cb49f45fdb875dd9543347))
8.6.85
2026-07-08 04:50:19 +00:00
Manuel 2728fcbabc fix: GraphQL variable-coercion suggestions disclose schema to unauthenticated callers ([GHSA-9g8f-h8f3-hjcm](https://github.com/parse-community/parse-server/security/advisories/GHSA-9g8f-h8f3-hjcm)) (#10564) 2026-07-08 06:49:11 +02:00
semantic-release-bot e66482b00e chore(release): 8.6.84 [skip ci]
## [8.6.84](https://github.com/parse-community/parse-server/compare/8.6.83...8.6.84) (2026-06-25)

### Bug Fixes

* Stored XSS via malformed Content-Type bypassing file upload extension blocklist ([GHSA-r899-h629-j84r](https://github.com/parse-community/parse-server/security/advisories/GHSA-r899-h629-j84r)) ([#10523](https://github.com/parse-community/parse-server/issues/10523)) ([55eab32](https://github.com/parse-community/parse-server/commit/55eab321fa02ad886e38ad2a19b101c9868e6757))
8.6.84
2026-06-25 09:10:46 +00:00
Manuel 55eab321fa fix: Stored XSS via malformed Content-Type bypassing file upload extension blocklist ([GHSA-r899-h629-j84r](https://github.com/parse-community/parse-server/security/advisories/GHSA-r899-h629-j84r)) (#10523) 2026-06-25 11:09:37 +02:00
semantic-release-bot 700a86760f chore(release): 8.6.83 [skip ci]
## [8.6.83](https://github.com/parse-community/parse-server/compare/8.6.82...8.6.83) (2026-06-19)

### Bug Fixes

* LiveQuery discloses object data to a subscriber across an ACL read-access change ([GHSA-97pr-9hgg-3p8r](https://github.com/parse-community/parse-server/security/advisories/GHSA-97pr-9hgg-3p8r)) ([#10516](https://github.com/parse-community/parse-server/issues/10516)) ([c9b24ce](https://github.com/parse-community/parse-server/commit/c9b24cecfee76d8563019adaacbcbd78471dc41e))
8.6.83
2026-06-19 00:15:22 +00:00
Manuel c9b24cecfe fix: LiveQuery discloses object data to a subscriber across an ACL read-access change ([GHSA-97pr-9hgg-3p8r](https://github.com/parse-community/parse-server/security/advisories/GHSA-97pr-9hgg-3p8r)) (#10516) 2026-06-19 02:14:17 +02:00
semantic-release-bot 9c8063175b chore(release): 8.6.82 [skip ci]
## [8.6.82](https://github.com/parse-community/parse-server/compare/8.6.81...8.6.82) (2026-06-17)

### Bug Fixes

* Denial of service via exponential-time processing of deeply nested query operators ([GHSA-cgxm-vr2f-6fj8](https://github.com/parse-community/parse-server/security/advisories/GHSA-cgxm-vr2f-6fj8)) ([#10512](https://github.com/parse-community/parse-server/issues/10512)) ([0f5d2ad](https://github.com/parse-community/parse-server/commit/0f5d2ad77b422dc904458254548be87397fc6e9b))
8.6.82
2026-06-17 14:23:01 +00:00
Manuel 0f5d2ad77b fix: Denial of service via exponential-time processing of deeply nested query operators ([GHSA-cgxm-vr2f-6fj8](https://github.com/parse-community/parse-server/security/advisories/GHSA-cgxm-vr2f-6fj8)) (#10512) 2026-06-17 16:21:38 +02:00
semantic-release-bot bccd92c768 chore(release): 8.6.81 [skip ci]
## [8.6.81](https://github.com/parse-community/parse-server/compare/8.6.80...8.6.81) (2026-06-16)

### Bug Fixes

* Stored XSS via non-standard file extension bypassing file upload extension blocklist ([GHSA-v8x7-r927-cc93](https://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93)) ([#10506](https://github.com/parse-community/parse-server/issues/10506)) ([97c6a78](https://github.com/parse-community/parse-server/commit/97c6a78d19f976ec756c1295f08a8fccab90799a))
8.6.81
2026-06-16 00:44:09 +00:00
Manuel 97c6a78d19 fix: Stored XSS via non-standard file extension bypassing file upload extension blocklist ([GHSA-v8x7-r927-cc93](https://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93)) (#10506) 2026-06-16 02:42:57 +02:00
semantic-release-bot c78cae6f09 chore(release): 8.6.80 [skip ci]
## [8.6.80](https://github.com/parse-community/parse-server/compare/8.6.79...8.6.80) (2026-06-03)

### Bug Fixes

* Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL ([GHSA-wmwx-jr2p-4j4r](https://github.com/parse-community/parse-server/security/advisories/GHSA-wmwx-jr2p-4j4r)) ([#10494](https://github.com/parse-community/parse-server/issues/10494)) ([efef11b](https://github.com/parse-community/parse-server/commit/efef11bc2dac50b994607adca66e2901075ab640))
8.6.80
2026-06-03 23:54:50 +00:00
Manuel efef11bc2d fix: Relation $relatedTo query bypasses protectedFields and owning-object ACL ([GHSA-wmwx-jr2p-4j4r](https://github.com/parse-community/parse-server/security/advisories/GHSA-wmwx-jr2p-4j4r)) (#10494) 2026-06-04 01:53:37 +02:00
semantic-release-bot d0048ff8d2 chore(release): 8.6.79 [skip ci]
## [8.6.79](https://github.com/parse-community/parse-server/compare/8.6.78...8.6.79) (2026-06-01)

### Bug Fixes

* Stored XSS via trailing-dot filename bypassing file upload extension blocklist ([GHSA-7wqv-xjf3-x35v](https://github.com/parse-community/parse-server/security/advisories/GHSA-7wqv-xjf3-x35v)) ([#10490](https://github.com/parse-community/parse-server/issues/10490)) ([9e99279](https://github.com/parse-community/parse-server/commit/9e992797ebd47df8143d4530fce4cc46fefb6532))
8.6.79
2026-06-01 21:38:07 +00:00
Manuel 9e992797eb fix: Stored XSS via trailing-dot filename bypassing file upload extension blocklist ([GHSA-7wqv-xjf3-x35v](https://github.com/parse-community/parse-server/security/advisories/GHSA-7wqv-xjf3-x35v)) (#10490) 2026-06-01 23:36:40 +02:00
semantic-release-bot 4a7fd10bae chore(release): 8.6.78 [skip ci]
## [8.6.78](https://github.com/parse-community/parse-server/compare/8.6.77...8.6.78) (2026-05-18)

### Bug Fixes

* GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj](https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj)) ([#10468](https://github.com/parse-community/parse-server/issues/10468)) ([a0ddb85](https://github.com/parse-community/parse-server/commit/a0ddb850e1060908f7aac3755861fb4a3d364127))
8.6.78
2026-05-18 16:57:30 +00:00
Manuel a0ddb850e1 fix: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj](https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj)) (#10468) 2026-05-18 18:56:10 +02:00
semantic-release-bot baa153c490 chore(release): 8.6.77 [skip ci]
## [8.6.77](https://github.com/parse-community/parse-server/compare/8.6.76...8.6.77) (2026-05-17)

### Bug Fixes

* Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm](https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm)) ([#10464](https://github.com/parse-community/parse-server/issues/10464)) ([8523425](https://github.com/parse-community/parse-server/commit/8523425525a16bbff13fa9718ca356a7e48caa0d))
8.6.77
2026-05-17 14:12:32 +00:00
Manuel 8523425525 fix: Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm](https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm)) (#10464) 2026-05-17 15:11:27 +01:00
semantic-release-bot ea543b1049 chore(release): 8.6.76 [skip ci]
## [8.6.76](https://github.com/parse-community/parse-server/compare/8.6.75...8.6.76) (2026-04-26)

### Bug Fixes

* MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) ([#10449](https://github.com/parse-community/parse-server/issues/10449)) ([8681c60](https://github.com/parse-community/parse-server/commit/8681c600c5fe2924c9d6ae805482bbb2896d2958))
8.6.76
2026-04-26 02:13:13 +00:00
Manuel 8681c600c5 fix: MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) (#10449) 2026-04-26 03:12:03 +01:00
semantic-release-bot 1b2107eb73 chore(release): 8.6.75 [skip ci]
## [8.6.75](https://github.com/parse-community/parse-server/compare/8.6.74...8.6.75) (2026-04-06)

### Bug Fixes

* Endpoint `/sessions/me` bypasses `_Session` `protectedFields` ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) ([#10407](https://github.com/parse-community/parse-server/issues/10407)) ([6ecc642](https://github.com/parse-community/parse-server/commit/6ecc6422c8624ba89a0fa71090d2c5f45d07d8de))
8.6.75
2026-04-06 16:47:52 +00:00
Manuel 6ecc6422c8 fix: Endpoint /sessions/me bypasses _Session protectedFields ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) (#10407) 2026-04-06 17:46:40 +01:00
semantic-release-bot 4b6966106f chore(release): 8.6.74 [skip ci]
## [8.6.74](https://github.com/parse-community/parse-server/compare/8.6.73...8.6.74) (2026-04-05)

### Bug Fixes

* Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) ([#10399](https://github.com/parse-community/parse-server/issues/10399)) ([1be6c97](https://github.com/parse-community/parse-server/commit/1be6c97494ab31cb93107c501d619c4f8b7d8e56))
8.6.74
2026-04-05 17:00:12 +00:00
Manuel 1be6c97494 fix: Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) (#10399) 2026-04-05 17:58:38 +01:00
semantic-release-bot 1750456f82 chore(release): 8.6.73 [skip ci]
## [8.6.73](https://github.com/parse-community/parse-server/compare/8.6.72...8.6.73) (2026-04-02)

### Bug Fixes

* File upload Content-Type override via extension mismatch ([GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc)) ([#10384](https://github.com/parse-community/parse-server/issues/10384)) ([0de3e9f](https://github.com/parse-community/parse-server/commit/0de3e9f4bd477b0f0866f519974f513060876c04))
8.6.73
2026-04-02 01:22:25 +00:00
Manuel 0de3e9f4bd fix: File upload Content-Type override via extension mismatch ([GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc)) (#10384) 2026-04-02 02:21:08 +01:00
semantic-release-bot 8191b6d3e6 chore(release): 8.6.72 [skip ci]
## [8.6.72](https://github.com/parse-community/parse-server/compare/8.6.71...8.6.72) (2026-03-31)

### Bug Fixes

* Security upgrade @apollo/server from 4.12.1 to 4.13.0 ([#10082](https://github.com/parse-community/parse-server/issues/10082)) ([18a1560](https://github.com/parse-community/parse-server/commit/18a1560d480d5bdcacbc24dbb7e45c02d7f93613))
8.6.72
2026-03-31 02:41:32 +00:00
Prafull 18a1560d48 fix: Security upgrade @apollo/server from 4.12.1 to 4.13.0 (#10082) 2026-03-31 03:40:28 +01:00
semantic-release-bot 9acb5cf202 chore(release): 8.6.71 [skip ci]
## [8.6.71](https://github.com/parse-community/parse-server/compare/8.6.70...8.6.71) (2026-03-30)

### Bug Fixes

* Streaming file download bypasses afterFind file trigger authorization ([GHSA-hpm8-9qx6-jvwv](https://github.com/parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv)) ([#10362](https://github.com/parse-community/parse-server/issues/10362)) ([053109b](https://github.com/parse-community/parse-server/commit/053109b3ee71815bc39ed84116c108ff9edbf337))
8.6.71
2026-03-30 23:19:35 +00:00
Manuel 053109b3ee fix: Streaming file download bypasses afterFind file trigger authorization ([GHSA-hpm8-9qx6-jvwv](https://github.com/parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv)) (#10362) 2026-03-31 00:18:32 +01:00
semantic-release-bot 83e7949196 chore(release): 8.6.70 [skip ci]
## [8.6.70](https://github.com/parse-community/parse-server/compare/8.6.69...8.6.70) (2026-03-29)

### Bug Fixes

* LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) ([#10351](https://github.com/parse-community/parse-server/issues/10351)) ([ffad0ec](https://github.com/parse-community/parse-server/commit/ffad0ec6b971ee0dd9545e1bf1fb34ddebf275c2))
8.6.70
2026-03-29 18:38:16 +00:00
Manuel ffad0ec6b9 fix: LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) (#10351) 2026-03-29 19:37:12 +01:00
semantic-release-bot 9702abd3dd chore(release): 8.6.69 [skip ci]
## [8.6.69](https://github.com/parse-community/parse-server/compare/8.6.68...8.6.69) (2026-03-29)

### Bug Fixes

* Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) ([#10348](https://github.com/parse-community/parse-server/issues/10348)) ([ebccd7f](https://github.com/parse-community/parse-server/commit/ebccd7fe2708007e62f705ee1c820a6766178777))
8.6.69
2026-03-29 03:57:16 +00:00
Manuel ebccd7fe27 fix: Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) (#10348) 2026-03-29 04:56:09 +01:00
semantic-release-bot fbd138cc26 chore(release): 8.6.68 [skip ci]
## [8.6.68](https://github.com/parse-community/parse-server/compare/8.6.67...8.6.68) (2026-03-29)

### Bug Fixes

* GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c](https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c)) ([#10345](https://github.com/parse-community/parse-server/issues/10345)) ([ea15412](https://github.com/parse-community/parse-server/commit/ea15412795f34594cc8a674fe858d445675e0295))
8.6.68
2026-03-29 01:34:18 +00:00
Manuel ea15412795 fix: GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c](https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c)) (#10345) 2026-03-29 02:32:53 +01:00
semantic-release-bot 7e4b4c13f9 chore(release): 8.6.67 [skip ci]
## [8.6.67](https://github.com/parse-community/parse-server/compare/8.6.66...8.6.67) (2026-03-28)

### Bug Fixes

* Cloud function validator bypass via prototype chain traversal ([GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) ([#10343](https://github.com/parse-community/parse-server/issues/10343)) ([4fc48cf](https://github.com/parse-community/parse-server/commit/4fc48cf28f22eea200d74d883505f485234a48d7))
8.6.67
2026-03-28 20:05:11 +00:00
Manuel 4fc48cf28f fix: Cloud function validator bypass via prototype chain traversal ([GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) (#10343) 2026-03-28 20:04:08 +00:00
semantic-release-bot 4fda17ccc1 chore(release): 8.6.66 [skip ci]
## [8.6.66](https://github.com/parse-community/parse-server/compare/8.6.65...8.6.66) (2026-03-27)

### Bug Fixes

* GraphQL API endpoint ignores CORS origin restriction ([GHSA-q3p6-g7c4-829c](https://github.com/parse-community/parse-server/security/advisories/GHSA-q3p6-g7c4-829c)) ([#10335](https://github.com/parse-community/parse-server/issues/10335)) ([0347641](https://github.com/parse-community/parse-server/commit/0347641507891d0013ec57f7c10f012064f41263))
8.6.66
2026-03-27 15:05:11 +00:00
Manuel 0347641507 fix: GraphQL API endpoint ignores CORS origin restriction ([GHSA-q3p6-g7c4-829c](https://github.com/parse-community/parse-server/security/advisories/GHSA-q3p6-g7c4-829c)) (#10335) 2026-03-27 15:04:01 +00:00
semantic-release-bot 9793e8fbb2 chore(release): 8.6.65 [skip ci]
## [8.6.65](https://github.com/parse-community/parse-server/compare/8.6.64...8.6.65) (2026-03-27)

### Bug Fixes

* LiveQuery protected field leak via shared mutable state across concurrent subscribers ([GHSA-m983-v2ff-wq65](https://github.com/parse-community/parse-server/security/advisories/GHSA-m983-v2ff-wq65)) ([#10331](https://github.com/parse-community/parse-server/issues/10331)) ([5834e29](https://github.com/parse-community/parse-server/commit/5834e29234593addaa0251a85f572ad4f376320b))
8.6.65
2026-03-27 13:45:34 +00:00
Manuel 5834e29234 fix: LiveQuery protected field leak via shared mutable state across concurrent subscribers ([GHSA-m983-v2ff-wq65](https://github.com/parse-community/parse-server/security/advisories/GHSA-m983-v2ff-wq65)) (#10331) 2026-03-27 13:44:20 +00:00
semantic-release-bot cf886438e6 chore(release): 8.6.64 [skip ci]
## [8.6.64](https://github.com/parse-community/parse-server/compare/8.6.63...8.6.64) (2026-03-26)

### Bug Fixes

* MFA single-use token bypass via concurrent authData login requests ([GHSA-w73w-g5xw-rwhf](https://github.com/parse-community/parse-server/security/advisories/GHSA-w73w-g5xw-rwhf)) ([#10327](https://github.com/parse-community/parse-server/issues/10327)) ([661f160](https://github.com/parse-community/parse-server/commit/661f160edac8daac0486bc94413cf9652876ab92))
8.6.64
2026-03-26 23:38:06 +00:00
Manuel 661f160eda fix: MFA single-use token bypass via concurrent authData login requests ([GHSA-w73w-g5xw-rwhf](https://github.com/parse-community/parse-server/security/advisories/GHSA-w73w-g5xw-rwhf)) (#10327) 2026-03-26 23:36:48 +00:00
semantic-release-bot a536a850b9 chore(release): 8.6.63 [skip ci]
## [8.6.63](https://github.com/parse-community/parse-server/compare/8.6.62...8.6.63) (2026-03-26)

### Bug Fixes

* Auth data exposed via verify password endpoint ([GHSA-wp76-gg32-8258](https://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258)) ([#10324](https://github.com/parse-community/parse-server/issues/10324)) ([a1d4e7b](https://github.com/parse-community/parse-server/commit/a1d4e7b12a12f16d3870dbee582a36765858e94c))
8.6.63
2026-03-26 20:36:45 +00:00
Manuel a1d4e7b12a fix: Auth data exposed via verify password endpoint ([GHSA-wp76-gg32-8258](https://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258)) (#10324) 2026-03-26 20:35:35 +00:00
semantic-release-bot 4ff8b79922 chore(release): 8.6.62 [skip ci]
## [8.6.62](https://github.com/parse-community/parse-server/compare/8.6.61...8.6.62) (2026-03-22)

### Bug Fixes

* Reject invalid locale format in PagesRouter ([#10282](https://github.com/parse-community/parse-server/issues/10282)) ([e047da9](https://github.com/parse-community/parse-server/commit/e047da961a4e911c3e110fc5534207a2d9b5ea35))
8.6.62
2026-03-22 17:34:23 +00:00
Manuel e047da961a fix: Reject invalid locale format in PagesRouter (#10282) 2026-03-22 17:33:10 +00:00
semantic-release-bot 99fcbb3a80 chore(release): 8.6.61 [skip ci]
## [8.6.61](https://github.com/parse-community/parse-server/compare/8.6.60...8.6.61) (2026-03-22)

### Bug Fixes

* Auth data exposed via /users/me endpoint ([GHSA-37mj-c2wf-cx96](https://github.com/parse-community/parse-server/security/advisories/GHSA-37mj-c2wf-cx96)) ([#10279](https://github.com/parse-community/parse-server/issues/10279)) ([5b8998e](https://github.com/parse-community/parse-server/commit/5b8998e6866bcf75be7b5bb625e27d23bfaf912c))
8.6.61
2026-03-22 03:49:01 +00:00
Manuel 5b8998e686 fix: Auth data exposed via /users/me endpoint ([GHSA-37mj-c2wf-cx96](https://github.com/parse-community/parse-server/security/advisories/GHSA-37mj-c2wf-cx96)) (#10279) 2026-03-22 03:48:02 +00:00