Device Token Deduplication Vulnerability in Parse Server by Parse Community
CVE-2026-100631
What is CVE-2026-100631?
Parse Server, an open source backend server, is susceptible to a vulnerability where the deduplication logic for device tokens fails to validate client-supplied installation fields. This allows an unauthenticated remote attacker, armed only with the public application ID, to inject query operators into database queries. The resultant deduplication cleanup can lead to the unintended deletion of all device registrations or a specific subset thereof. Once deleted, these registrations cannot be recovered without requiring client re-registration, disrupting push notification services. This issue affects any deployment that opens the REST API for client usage and employs push notifications under default settings. Versions 8.6.90 and 9.10.1-alpha.9 resolve the problem by enforcing stringent checks on input values and restricting the deduplication process to the calling application.
Affected Version(s)
parse-server 9.0.0 < 9.10.1-alpha.9
parse-server 0 < 8.6.90
parse-server 9.10.1-alpha.9
