Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
Parse Server: MFA recovery code single-use bypass via concurrent requests
GraphQL: Security breach on Viewer query
parse-server new anonymous user session acts as if it's created with password
Parse Server before v3.4.1 vulnerable to Denial of Service
Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance
Parse Server vulnerable to brute force guessing of user sensitive data via search patterns
receiving subscription objects with deleted session
Parse Server exposes auth data via /users/me endpoint
Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter
Parse Server's Cloud function dispatch crashes server via prototype chain traversal
Other Backend as a Service projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Parse Server โ without relying on volunteer maintainers.
Talk to an Expert โ