CVE-2026-30854 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3.1-alpha.3 to before version 9.5.0-alpha…
Medium CVSS: 6.9

CVE-2026-30854

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3.1-alpha.3 to before version 9.5.0-alpha.10, when graphQLPublicIntrospection is disabled, __type queries nested inside inline fragments (e.g. ... on Query { __type(name:"User") { name } }) bypass the introspection control, allowing unauthenticated users to perform type reconnaissance. __schema introspection is not affected. This issue has been patched in version 9.5.0-alpha.10.
Vendor
Parseplatform
Product
Parse-server
CWE
CWE-863
Yayın Tarihi
2026-03-07 17:15:52
Güncelleme
2026-03-10 16:52:21
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar