PT-2026-23754 · Unknown · Parse Server

Fancymalware

·

Published

2026-03-06

·

Updated

2026-03-11

·

CVE-2026-30835

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 8.6.7 Parse Server versions prior to 9.5.0-alpha.6
Description Parse Server is an open-source backend deployable on Node.js infrastructures. A malformed $regex query parameter, such as [abc), can cause the database to return a structured error object unsanitized through the API response. This exposes database internals, including error messages, error codes, code names, cluster timestamps, and topology details. The issue is exploitable by any client capable of sending query requests, contingent on the deployment’s permission settings. The vulnerable parameter is $regex. The API endpoint receiving the vulnerable parameter is not specified.
Recommendations Upgrade to Parse Server version 8.6.7 or later. Upgrade to Parse Server version 9.5.0-alpha.6 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-30835
CVE-2026-30835
GHSA-9CP7-3Q5W-J92G

Affected Products

Parse Server