CVE-2026-105828: Parse Server 9.0.0 before 9.10.1-alpha.12 Class Name Disclosure via GraphQL Errors
Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public introspection is disabled. Unauthenticated attackers holding only the public Application Id can send crafted operations triggering unknown-argument or invalid enum value errors to learn pointer and relation target classes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Parse Serverto a version that resolves this vulnerability.Fixed in 8.6.92 - Upgrade
Upgrade
Parse Serverto a version that resolves this vulnerability.Fixed in 9.10.1-alpha.12
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker needs only the public Parse Application Id. They can submit crafted GraphQL operations without credentials.
Does disabling public GraphQL introspection prevent the disclosure?
No. The issue specifically discloses hidden class names through GraphQL validation errors even when public introspection is disabled.
What information can an attacker obtain?
Crafted operations that trigger unknown-argument or invalid enum-value errors can reveal target class names used by pointer and relation fields.
Which Parse Server releases are affected?
Affected ranges are Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12.