Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qpc3-fg4j-8hgm | Parse Server has a protected field change detection oracle via LiveQuery watch parameter |
Wed, 25 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parseplatform
Parseplatform parse-server |
|
| CPEs | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha10:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha11:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha12:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha13:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha14:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha15:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha16:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha17:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha18:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha19:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha1:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha20:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha21:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha22:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha23:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha24:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha25:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha26:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha27:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha28:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha29:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha2:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha30:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha31:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha32:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha33:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha34:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha35:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha36:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha37:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha38:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha39:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha3:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha40:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha41:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha42:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha4:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha5:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha6:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha7:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha8:*:*:*:node.js:*:* cpe:2.3:a:parseplatform:parse-server:9.6.0:alpha9:*:*:*:node.js:*:* |
|
| Vendors & Products |
Parseplatform
Parseplatform parse-server |
|
| Metrics |
cvssV3_1
|
Wed, 25 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parse Community
Parse Community parse Server |
|
| Vendors & Products |
Parse Community
Parse Community parse Server |
Tue, 24 Mar 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.54 and 9.6.0-alpha.43, an attacker can subscribe to LiveQuery with a watch parameter targeting a protected field. Although the protected field value is properly stripped from event payloads, the presence or absence of update events reveals whether the protected field changed, creating a binary oracle. For boolean protected fields, the timing of change events is equivalent to knowing the field value. This issue has been patched in versions 8.6.54 and 9.6.0-alpha.43. | |
| Title | Parse Server: Protected field change detection oracle via LiveQuery watch parameter | |
| Weaknesses | CWE-203 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T13:34:05.792Z
Reserved: 2026-03-19T18:45:22.434Z
Link: CVE-2026-33429
Updated: 2026-03-25T13:33:58.051Z
Status : Analyzed
Published: 2026-03-24T19:16:53.883
Modified: 2026-03-25T21:22:23.367
Link: CVE-2026-33429
No data.
OpenCVE Enrichment
Updated: 2026-03-26T12:19:00Z
Github GHSA