CVE-2026-31901Disclosure(parseplatform / parse-server)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endpoint (/verificationEmailRequest) returns distinct error responses depending on whether an email address belongs to an existing user, is already verified, or does not exist. An attacker can send requests with different email addresses and observe the error codes to determine which email addresses are registered in the application. This is a user enumeration vulnerability that affects any Parse Server deployment with email verification enabled (verifyUserEmails: true). This vulnerability is fixed in 8.6.34 and 9.6.0-alpha.8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-204

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-11: 2Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-11: 103-11
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-31901 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endp… https://www.cve.org/CVERecord?id=CVE-2026-31901 ----- Traducción: CVE-2026-31901 Par… http://infoflow.cloud`

    Post summary

    The text briefly announces CVE‑2026‑31901 as affecting Parse Server, linking to the official record, but provides no proof‑of‑concept, exploit details, patch notes, or technical depth.

    0000026
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31901 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endp… https://www.cve.org/CVERecord?id=CVE-2026-31901

    Post summary

    The post announces CVE-2026-31901 as a vulnerability in Parse Server’s email verification endpoint, identifying affected versions and indicating that newer releases include a fix.

    00000191
    56.6K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-
Appparseplatformparse-server9.6.0node.js-

Explore more