An express module providing a Parse-compatible API server
82%
Total Score
95
100
100
65
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-43930 parse-server is vulnerable to Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in versions 9.0.0 - 9.9.0-alpha.2 and 0.0.0 - 8.6.76. | 0.0.0 - 8.6.769.0.0 - 9.9.0-alpha.2 | Low |
AIKIDO-2026-10693 parse-server is vulnerable to Race Condition in versions 9.0.0 - 9.8.0 and 1.0.0 - 8.6.75. | 1.0.0 - 8.6.759.0.0 - 9.8.0 | Low |
AIKIDO-2026-10607 parse-server is vulnerable to Authentication Bypass in versions 6.0.0 - 8.6.75. | 6.0.0 - 8.6.75 | Low |
CVE-2026-39381 parse-server is vulnerable to Incorrect Authorization in versions 9.0.0 - 9.8.0-alpha.7 and 7.0.0 - 8.6.75. | 7.0.0 - 8.6.759.0.0 - 9.8.0-alpha.7 | Medium |
CVE-2026-39321 parse-server is vulnerable to Observable Timing Discrepancy in versions 9.0.0 - 9.8.0-alpha.6 and 0.0.0 - 8.6.74. | 0.0.0 - 8.6.749.0.0 - 9.8.0-alpha.6 | Low |
| Dependency | Last Release | Score |
|---|---|---|
ws Version 8.20.0 | — | — |
tv4 Version 1.3.0 | — | — |
cors Version 2.8.6 | — | — |
mime Version 4.1.0 | — | — |
parse Version 8.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant