CVE-2026-34373High· 8.8▾ TwilightParse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditiona…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditionally allows cross-origin requests from any website. This bypasses origin restrictions that operators configure to control which websites can interact with the Parse Server API. The REST API correctly enforces the configured allowOrigin restriction. This issue has been patched in versions 8.6.66 and 9.7.0-alpha.10.
parse-server >= 3.5.0, < 8.6.66parse-server >= 9.0.0, < 9.7.0parse-server = 9.7.0Upgrade past the affected range:
parse-server 9.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87806High· 7.4Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter
CVE-2026-34363Medium· 5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34224Medium· 4.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34595Medium· 4.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34574Medium· 5.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
CVE-2026-34573High· 7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js