8.2
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its validators on storage adapters that support streaming (e.g. the default GridFS adapter). This allows access to files that should be protected by afterFind trigger authorization logic or built-in validators such as requireUser. This issue has been patched in versions 8.6.71 and 9.7.1-alpha.1.
Basic Information
ID
CVE-2026-34784
Source
GitHub_M
Published
Mar 31, 2026 at 19:39
Modified
Mar 31, 2026 at 20:29
Affected Product
Vendor
parse-community
Product
parse-server
Version
< 8.6.71
Affected Versions
parse-community parse-server < 8.6.71
parse-community parse-server >= 9.0.0, < 9.7.1-alpha.1
parse-community parse-server >= 9.0.0, < 9.7.1-alpha.1
CWE Classification
References
- github.com /parse-community/parse-server/security/advisories/GHSA-hpm8-9qx6-jvwv
- github.com /parse-community/parse-server/pull/10361
- github.com /parse-community/parse-server/pull/10362
- github.com /parse-community/parse-server/commit/053109b3ee71815bc39ed84116c108ff9edbf337
- github.com /parse-community/parse-server/commit/a0b0c69fc44f87f80d793d257344e7dcbf676e22