Device Token Deduplication Vulnerability in Parse Server by Parse Community
CVE-2026-100631

8.7HIGH

Key Information:

Vendor
CVE Published:
26 September 2026

What is CVE-2026-100631?

Parse Server, an open source backend server, is susceptible to a vulnerability where the deduplication logic for device tokens fails to validate client-supplied installation fields. This allows an unauthenticated remote attacker, armed only with the public application ID, to inject query operators into database queries. The resultant deduplication cleanup can lead to the unintended deletion of all device registrations or a specific subset thereof. Once deleted, these registrations cannot be recovered without requiring client re-registration, disrupting push notification services. This issue affects any deployment that opens the REST API for client usage and employs push notifications under default settings. Versions 8.6.90 and 9.10.1-alpha.9 resolve the problem by enforcing stringent checks on input values and restricting the deduplication process to the calling application.

Affected Version(s)

parse-server 9.0.0 < 9.10.1-alpha.9

parse-server 0 < 8.6.90

parse-server 9.10.1-alpha.9

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
mtrezza
.