CVE-2026-34363Disclosure(parseplatform / parse-server)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers process each subscriber concurrently using shared mutable objects. The sensitive data filter modifies these shared objects in-place, so when one subscriber's filter removes a protected field, subsequent subscribers may receive the already-filtered object. This can cause protected fields and authentication data to leak to clients that should not see them, or cause clients that should see the data to receive an incomplete object. Additionally, when an afterEvent Cloud Code trigger is registered, one subscriber's trigger modifications can leak to other subscribers through the same shared mutable state. Any Parse Server deployment using LiveQuery with protected fields or afterEvent triggers is affected when multiple clients subscribe to the same class. This issue has been patched in versions 8.6.65 and 9.7.0-alpha.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-31: 2Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 103-31
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34363 - Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers Intel Report: https://ift.tt/OiMPBSL

    Post summary

    The post alerts about CVE-2026-34363, a protected field leak in Parse Server’s LiveQuery caused by shared mutable state among concurrent subscribers, but does not provide a PoC, exploit, patch, or mention active exploitation.

    00000223
    281 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34363 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clie… https://www.cve.org/CVERecord?id=CVE-2026-34363

    Post summary

    The text announces that a vulnerability exists in Parse Server prior to certain releases, but it provides no detailed technical data or evidence of exploitation.

    0000047
    56.9K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-
Appparseplatformparse-server9.7.0node.js-

Explore more