Manuel
|
e9c85dfe40
|
fix: LiveQuery discloses object data to a subscriber across an ACL read-access change ([GHSA-97pr-9hgg-3p8r](https://github.com/parse-community/parse-server/security/advisories/GHSA-97pr-9hgg-3p8r)) (#10515)
|
2026-06-19 02:13:55 +02:00 |
|
Manuel
|
1103c7a890
|
fix: Denial of service via exponential-time processing of deeply nested query operators ([GHSA-cgxm-vr2f-6fj8](https://github.com/parse-community/parse-server/security/advisories/GHSA-cgxm-vr2f-6fj8)) (#10511)
|
2026-06-17 16:21:23 +02:00 |
|
Manuel
|
be12a60d65
|
fix: Stored XSS via non-standard file extension bypassing file upload extension blocklist ([GHSA-v8x7-r927-cc93](https://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93)) (#10505)
|
2026-06-16 02:42:38 +02:00 |
|
Manuel
|
30f1612a2d
|
test: LiveQuery cross-origin connections receive only public-read data (#10504)
|
2026-06-13 23:16:40 +02:00 |
|
Manuel
|
f8612109e3
|
fix: Middleware route checks do not match routing-equivalent path variants (trailing slash, case) (#10501)
|
2026-06-12 13:03:10 +02:00 |
|
Manuel
|
880e8e6929
|
fix: rateLimit on exact static routes is bypassed by appending a query string (#10500)
|
2026-06-11 03:11:49 +02:00 |
|
Manuel
|
3fad4fb1c4
|
fix: LiveQuery subscriptions leak when a client reuses a subscribe requestId (#10499)
|
2026-06-11 01:48:30 +02:00 |
|
Manuel
|
f12e1c3e31
|
fix: Cloud Function multipart requests bypass the maxUploadSize limit (#10498)
|
2026-06-06 02:43:56 +02:00 |
|
Manuel
|
78859a9bc7
|
docs: Clarify that rateLimit applies to REST API routes only and not to GraphQL operations (#10496)
|
2026-06-05 00:40:33 +02:00 |
|
Manuel
|
43658f1fd8
|
fix: Relation $relatedTo query bypasses protectedFields and owning-object ACL ([GHSA-wmwx-jr2p-4j4r](https://github.com/parse-community/parse-server/security/advisories/GHSA-wmwx-jr2p-4j4r)) (#10493)
|
2026-06-04 01:52:43 +02:00 |
|
Manuel
|
83e90edbe4
|
fix: Endpoints /login and /verifyPassword disclose MFA secrets and protected fields when _User get is denied ([GHSA-75v4-m273-5j49](https://github.com/parse-community/parse-server/security/advisories/GHSA-75v4-m273-5j49)) (#10492)
|
2026-06-03 16:41:16 +02:00 |
|
Manuel
|
66484ce8fd
|
fix: Stored XSS via trailing-dot filename bypassing file upload extension blocklist ([GHSA-7wqv-xjf3-x35v](https://github.com/parse-community/parse-server/security/advisories/GHSA-7wqv-xjf3-x35v)) (#10489)
|
2026-06-01 23:36:26 +02:00 |
|
Manuel
|
552c6dd754
|
fix: Server option routeAllowList is bypassable through batch sub-requests ([GHSA-p84r-h6rx-f2xr](https://github.com/parse-community/parse-server/security/advisories/GHSA-p84r-h6rx-f2xr)) (#10482)
|
2026-05-27 22:41:48 +02:00 |
|
Manuel
|
0ae0ed382b
|
test: GraphQL endpoint is exempt from routeAllowList by design (#10480)
|
2026-05-27 00:36:20 +02:00 |
|
Manuel
|
155123ade9
|
fix: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers ([GHSA-8cph-rgr4-g5vj](https://github.com/parse-community/parse-server/security/advisories/GHSA-8cph-rgr4-g5vj)) (#10467)
|
2026-05-18 17:04:56 +02:00 |
|
Manuel
|
56c159ec96
|
fix: Pre-authentication denial of service via client version header regex backtracking ([GHSA-38m6-82c8-4xfm](https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm)) (#10463)
|
2026-05-17 15:11:10 +01:00 |
|
Manuel
|
eb6441362a
|
build: Release (#10452)
|
2026-05-01 13:14:53 +01:00 |
|
Manuel
|
9fee1a0708
|
feat: Add installation deviceToken deduplication options (#10451)
|
2026-04-30 23:11:39 +01:00 |
|
Manuel
|
725be0d602
|
fix: MFA SMS one-time password accepted twice under concurrent login ([GHSA-jpq4-7fmq-q5fj](https://github.com/parse-community/parse-server/security/advisories/GHSA-jpq4-7fmq-q5fj)) (#10448)
|
2026-04-26 03:10:27 +01:00 |
|
Manuel
|
f26700e39d
|
feat: Add rawValues and rawFieldNames options for aggregation queries (#10438)
|
2026-04-17 09:12:18 +01:00 |
|
Manuel
|
fc53270dbe
|
test: Fix socket hang up in node-fetch 3.3.2 fails tests (#10443)
|
2026-04-17 01:39:53 +01:00 |
|
Manuel
|
f303f752c6
|
refactor: Bump node-fetch from 3.2.10 to 3.3.2 (#10441)
|
2026-04-17 01:52:11 +02:00 |
|
Manuel
|
163d7be605
|
refactor: Bump jsonwebtoken from 9.0.2 to 9.0.3 (#10440)
|
2026-04-17 01:19:05 +02:00 |
|
Manuel
|
cbd1da7be3
|
refactor: Bump path-to-regexp from 8.4.0 to 8.4.2 (#10439)
|
2026-04-16 13:39:55 +02:00 |
|
Manuel
|
b3dedd0482
|
build: Release (#10430)
|
2026-04-12 11:25:40 +01:00 |
|
Manuel
|
fd31159859
|
fix: Facebook Standard Login missing app ID validation (#10429)
|
2026-04-12 01:16:11 +01:00 |
|
Manuel
|
39af946200
|
refactor: Bump @babel/cli from 7.27.0 to 7.28.6 (#10424)
|
2026-04-10 21:45:42 +01:00 |
|
Manuel
|
8b80e55afd
|
refactor: Bump otpauth from 9.4.0 to 9.5.0 (#10423)
|
2026-04-10 21:22:07 +01:00 |
|
Manuel
|
b55880d702
|
refactor: Bump typescript-eslint from 8.53.1 to 8.58.0 (#10422)
|
2026-04-10 20:51:40 +01:00 |
|
Manuel
|
bf40004d25
|
feat: Add requestComplexity.subqueryLimit option to limit subquery results (#10420)
|
2026-04-10 16:49:34 +01:00 |
|
Manuel
|
18482e386c
|
feat: Add requestComplexity.allowRegex option to disable $regex query operator (#10418)
|
2026-04-09 18:12:12 +01:00 |
|
Manuel
|
d7d5ae56f7
|
test: Fix flaky LiveQuery tests caused by session token leak (#10415)
|
2026-04-08 00:36:45 +01:00 |
|
Manuel
|
7d4a4607fa
|
test: LiveQuery disconnect does not clear subscription info (#10414)
|
2026-04-08 00:11:55 +01:00 |
|
Manuel
|
c0889c8575
|
fix: Master key does not bypass protectedFields on various endpoints (#10412)
|
2026-04-07 13:48:39 +01:00 |
|
Manuel
|
8a3db3b966
|
fix: Endpoints /login and /verifyPassword ignore _User protectedFields (#10409)
|
2026-04-07 13:01:11 +01:00 |
|
Manuel
|
c136e2b7ab
|
fix: Endpoint /upgradeToRevocableSession ignores _Session protectedFields (#10408)
|
2026-04-07 10:09:09 +01:00 |
|
Manuel
|
d5075758f6
|
fix: Endpoint /sessions/me bypasses _Session protectedFields ([GHSA-g4v2-qx3q-4p64](https://github.com/parse-community/parse-server/security/advisories/GHSA-g4v2-qx3q-4p64)) (#10406)
|
2026-04-06 17:46:32 +01:00 |
|
Manuel
|
9168e69cb7
|
test: Webhook overwrites Cloud Code function warning (#10400)
|
2026-04-05 22:08:12 +01:00 |
|
Manuel
|
531b9ab6dd
|
fix: Login timing side-channel reveals user existence ([GHSA-mmpq-5hcv-hf2v](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmpq-5hcv-hf2v)) (#10398)
|
2026-04-05 17:48:57 +01:00 |
|
Manuel
|
f7f354226e
|
ci: Replace third-party GitHub Actions with trusted alternatives (#10397)
|
2026-04-04 20:00:25 +01:00 |
|
Manuel
|
a3f36a2ddb
|
feat: Add support for invoking Cloud Function with multipart/form-data protocol (#10395)
|
2026-04-04 17:46:51 +01:00 |
|
Manuel
|
fc117efa4d
|
feat: Add server option fileDownload to restrict file download (#10394)
|
2026-04-03 19:41:42 +01:00 |
|
Manuel
|
19716ad9af
|
fix: Bump lodash from 4.17.23 to 4.18.1 (#10393)
|
2026-04-03 19:01:02 +01:00 |
|
Manuel
|
a4bf3fe145
|
refactor: Bump semver from 7.7.2 to 7.7.4 (#10392)
|
2026-04-03 18:14:19 +01:00 |
|
Manuel
|
7d8b367e0b
|
fix: Maintenance key IP mismatch silently downgrades to regular auth instead of rejecting (#10391)
|
2026-04-03 17:36:27 +01:00 |
|
Manuel
|
f2d06e7b95
|
feat: Add route block with new server option routeAllowList (#10389)
|
2026-04-03 16:08:18 +01:00 |
|
Manuel
|
dd7cc41a95
|
fix: File upload Content-Type override via extension mismatch ([GHSA-vr5f-2r24-w5hc](https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hc)) (#10383)
|
2026-04-02 02:19:26 +01:00 |
|
Manuel
|
ead12bd1df
|
fix: Session field guard bypass via falsy values for ACL and user fields (#10382)
|
2026-04-01 21:25:30 +01:00 |
|
Manuel
|
b587767aa3
|
test: Plaintext password accessible in beforeSave trigger on _User class (#10380)
|
2026-04-01 20:40:18 +01:00 |
|
Manuel
|
df5cd46c83
|
refactor: Bump @parse/push-adapter from 8.3.1 to 8.4.0 (#10381)
|
2026-04-01 20:32:33 +01:00 |
|
Manuel
|
c7814b4429
|
refactor: Bump jsdoc from 4.0.4 to 4.0.5 (#10379)
|
2026-04-01 19:35:38 +01:00 |
|
Manuel
|
03be0c07e9
|
docs: Add multi-tenancy section to README (#10378)
|
2026-04-01 18:05:08 +01:00 |
|
Manuel
|
b4888948b5
|
refactor: Bump @graphql-tools/utils from 10.8.6 to 11.0.0 (#10377)
|
2026-04-01 17:55:25 +01:00 |
|
Manuel
|
225a4bb2ad
|
test: CLI execution tests fail on Node 22 due to late stderr callback (#10376)
|
2026-04-01 16:46:24 +01:00 |
|
Manuel
|
66350964c8
|
fix: Nested batch sub-requests cause unclear error (#10371)
|
2026-04-01 14:35:25 +01:00 |
|
Manuel
|
82edbd747c
|
refactor: Bump uuid from 11.1.0 to 13.0.0 (#10370)
|
2026-03-31 17:57:06 +01:00 |
|
Manuel
|
1cea69a6fa
|
refactor: Bump yaml from 2.8.2 to 2.8.3 (#10369)
|
2026-03-31 15:55:48 +01:00 |
|
Manuel
|
eae967cd53
|
refactor: Bump lint-staged from 16.2.7 to 16.4.0 (#10368)
|
2026-03-31 13:53:50 +01:00 |
|
Manuel
|
8a581e940f
|
refactor: Upgrade ws to 7.5.10 (GHSA-3h5v-q93c-6h6q) (#10363)
|
2026-03-31 02:41:17 +01:00 |
|
Manuel
|
a0b0c69fc4
|
fix: Streaming file download bypasses afterFind file trigger authorization ([GHSA-hpm8-9qx6-jvwv](https://github.com/parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv)) (#10361)
|
2026-03-31 00:17:57 +01:00 |
|
Manuel
|
54c835e0fa
|
refactor: Bump mime from 4.0.7 to 4.1.0 (#10360)
|
2026-03-30 20:38:12 +01:00 |
|
Manuel
|
2f7dd2e4bb
|
refactor: Bump express-rate-limit from 8.3.0 to 8.3.1 (#10359)
|
2026-03-30 19:32:34 +01:00 |
|
Manuel
|
2f2c548605
|
refactor: Bump @babel/preset-env from 7.27.2 to 7.29.2 (#10358)
|
2026-03-30 18:13:15 +01:00 |
|
Manuel
|
6d0bd1eb40
|
build: Release (#10354)
|
2026-03-30 01:30:17 +01:00 |
|
Manuel
|
aea7596cd2
|
feat: Extend storage adapter interface to optionally return matchedCount and modifiedCount from DatabaseController.update with many: true (#10353)
|
2026-03-30 01:09:10 +01:00 |
|
Manuel
|
d5f5128ade
|
fix: Cloud Code trigger context vulnerable to prototype pollution (#10352)
|
2026-03-30 00:21:18 +01:00 |
|
Manuel
|
f63fd1a3fe
|
fix: LiveQuery protected-field guard bypass via array-like logical operator value ([GHSA-mmg8-87c5-jrc2](https://github.com/parse-community/parse-server/security/advisories/GHSA-mmg8-87c5-jrc2)) (#10350)
|
2026-03-29 19:36:52 +01:00 |
|
Manuel
|
63c37c49c7
|
fix: Batch login sub-request rate limit uses IP-based keying (#10349)
|
2026-03-29 16:08:36 +01:00 |
|
Manuel
|
90802969fc
|
fix: Session field immutability bypass via falsy-value guard ([GHSA-f6j3-w9v3-cq22](https://github.com/parse-community/parse-server/security/advisories/GHSA-f6j3-w9v3-cq22)) (#10347)
|
2026-03-29 04:55:39 +01:00 |
|
Manuel
|
8dd7bf2f61
|
feat: Add support for partialFilterExpression in MongoDB storage adapter (#10346)
|
2026-03-29 03:37:19 +01:00 |
|
Manuel
|
f759bda075
|
fix: GraphQL complexity validator exponential fragment traversal DoS ([GHSA-mfj6-6p54-m98c](https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c)) (#10344)
|
2026-03-29 02:32:35 +01:00 |
|
Manuel
|
dc59e27266
|
fix: Cloud function validator bypass via prototype chain traversal ([GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) (#10342)
|
2026-03-28 18:46:42 +00:00 |
|
Manuel
|
9c83e1a504
|
refactor: Bump path-to-regexp from 8.3.0 to 8.4.0 (#10340)
|
2026-03-28 16:39:54 +00:00 |
|
Manuel
|
705855cfa4
|
refactor: Bump jasmine from 5.7.1 to 6.1.0 (#10338)
|
2026-03-28 16:10:57 +00:00 |
|
Manuel
|
97921cbc5c
|
refactor: Bump @semantic-release/github from 12.0.0 to 12.0.6 (#10337)
|
2026-03-27 20:03:29 +00:00 |
|
Manuel
|
c717cc8667
|
refactor: Bump @apollo/server from 5.4.0 to 5.5.0 (#10336)
|
2026-03-27 18:03:06 +00:00 |
|
Manuel
|
4dd0d3d8be
|
fix: GraphQL API endpoint ignores CORS origin restriction ([GHSA-q3p6-g7c4-829c](https://github.com/parse-community/parse-server/security/advisories/GHSA-q3p6-g7c4-829c)) (#10334)
|
2026-03-27 15:03:33 +00:00 |
|
Manuel
|
776c71c307
|
fix: LiveQuery protected field leak via shared mutable state across concurrent subscribers ([GHSA-m983-v2ff-wq65](https://github.com/parse-community/parse-server/security/advisories/GHSA-m983-v2ff-wq65)) (#10330)
|
2026-03-27 13:44:00 +00:00 |
|
Manuel
|
e7efbebba3
|
fix: MFA single-use token bypass via concurrent authData login requests ([GHSA-w73w-g5xw-rwhf](https://github.com/parse-community/parse-server/security/advisories/GHSA-w73w-g5xw-rwhf)) (#10326)
|
2026-03-26 23:37:10 +00:00 |
|
Manuel
|
2be73d9d7b
|
ci: Increase npm network timeout for Docker arm64 builds (#10325)
|
2026-03-26 21:04:27 +00:00 |
|
Manuel
|
770be86474
|
fix: Auth data exposed via verify password endpoint ([GHSA-wp76-gg32-8258](https://github.com/parse-community/parse-server/security/advisories/GHSA-wp76-gg32-8258)) (#10323)
|
2026-03-26 20:35:44 +00:00 |
|
Manuel
|
f537e677f0
|
test: Fix flaky tests (#10320)
|
2026-03-26 02:20:57 +00:00 |
|
Manuel
|
92791c1d1d
|
fix: Duplicate session destruction can cause unhandled promise rejection (#10319)
|
2026-03-26 01:41:45 +00:00 |
|
Manuel
|
eea27af3b1
|
ci: Remove feature to retry flaky tests (#10314)
|
2026-03-26 00:30:55 +00:00 |
|
Manuel
|
3ff818034a
|
refactor: Bump redis from 5.10.0 to 5.11.0 (#10317)
|
2026-03-25 23:56:19 +00:00 |
|
Manuel
|
af23b92a34
|
refactor: Bump graphql from 16.11.0 to 16.13.2 (#10315)
|
2026-03-25 22:18:51 +00:00 |
|
Manuel
|
cfbe7a04cc
|
test: Fix flaky tests (#10313)
|
2026-03-25 19:20:55 +00:00 |
|
Manuel
|
c5c43259d1
|
fix: Postgres query on non-existent column throws internal server error (#10308)
|
2026-03-25 00:07:06 +00:00 |
|
Manuel
|
3f888b1aac
|
refactor: Bump follow-redirects from 1.15.9 to 1.15.11 (#10307)
|
2026-03-24 20:10:01 +00:00 |
|
Manuel
|
1bacddb1e4
|
refactor: Bump ws from 8.18.2 to 8.20.0 (#10306)
|
2026-03-24 19:48:06 +00:00 |
|
Manuel
|
0f3717d4ee
|
refactor: Bump lru-cache from 11.2.6 to 11.2.7 (#10305)
|
2026-03-24 18:58:53 +00:00 |
|
Manuel
|
f12804800b
|
fix: Missing error messages in Parse errors (#10304)
|
2026-03-24 18:56:25 +00:00 |
|
Manuel
|
fe9fba61dd
|
test: Fix flaky test (#10303)
|
2026-03-24 15:52:45 +00:00 |
|
Manuel
|
6fcbb173d2
|
refactor: Bump lru-cache from 10.4.0 to 11.2.6 (#10302)
|
2026-03-24 15:41:17 +00:00 |
|
Manuel
|
9ec6f283a5
|
refactor: Bump semantic-release from 24.2.5 to 25.0.3 (#10297)
|
2026-03-24 03:01:04 +00:00 |
|
Manuel
|
1622f6af1c
|
refactor: Bump lint-staged from 16.1.0 to 16.2.7 (#10296)
|
2026-03-24 02:04:23 +00:00 |
|
Manuel
|
b344927b89
|
ci: Fix flaky GC tests (#10294)
|
2026-03-24 00:15:30 +00:00 |
|
Manuel
|
c77330d5a7
|
refactor: Unnecessary deprecation warning on enableProductPurchaseLegacyApi: false (#10293)
|
2026-03-23 23:07:17 +00:00 |
|
Manuel
|
6449397e86
|
refactor: Bump express-rate-limit from 8.2.1 to 8.3.0 (#10292)
|
2026-03-23 22:56:25 +00:00 |
|
Manuel
|
7c8b213d96
|
fix: Maintenance key blocked from querying protected fields (#10290)
|
2026-03-23 03:50:45 +00:00 |
|