๐Ÿ” CVE Alert

CVE-2026-105828

UNKNOWN 0.0

Parse Server 9.0.0 before 9.10.1-alpha.12 Class Name Disclosure via GraphQL Errors

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public introspection is disabled. Unauthenticated attackers holding only the public Application Id can send crafted operations triggering unknown-argument or invalid enum value errors to learn pointer and relation target classes.

CWE CWE-209
Vendor parse-community
Product parse-server
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for parse-community parse-server

Be the first to know when new unknown vulnerabilities affecting parse-community parse-server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

parse-community / parse-server
9.0.0 < 9.10.1-alpha.12
parse-community / parse-server
8.2.2 < 8.6.92

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/parse-community/parse-server/security/advisories/GHSA-6m77-f8xr-f723 vulncheck.com: https://www.vulncheck.com/advisories/parse-server-9.0.0-before-9.10.1-alpha.12-class-name-disclosure-via-graphql-errors

Credits

๐Ÿ” arpitjain099 mtrezza