CVE-2026-105828
Parse Server 9.0.0 before 9.10.1-alpha.12 Class Name Disclosure via GraphQL Errors
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public introspection is disabled. Unauthenticated attackers holding only the public Application Id can send crafted operations triggering unknown-argument or invalid enum value errors to learn pointer and relation target classes.
| CWE | CWE-209 |
| Vendor | parse-community |
| Product | parse-server |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for parse-community parse-server
Be the first to know when new unknown vulnerabilities affecting parse-community parse-server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
parse-community / parse-server
9.0.0 < 9.10.1-alpha.12
parse-community / parse-server
8.2.2 < 8.6.92
References
Credits
๐ arpitjain099 mtrezza