<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T05:02:09.498194+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-parse-2026-34574</id>
    <title>BIT-parse-2026-34574 — Parse Server: Session field immutability bypass via falsy-value guard</title>
    <updated>2026-10-06T05:02:09.550536+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: parse</p>
<p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by sending a null value in a PUT request to the session update endpoint. This allows nullifying the session expiry, making the session valid indefinitely and bypassing configured session length policies. This issue has been patched in versions 8.6.69 and 9.7.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-parse-2026-34574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278514</id>
    <title>EUVD-2026-278514</title>
    <updated>2026-10-06T05:02:09.550600+00:00</updated>
    <content>EUVD-2026-278514</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34574</id>
    <title>fkie_cve-2026-34574</title>
    <updated>2026-10-06T05:02:09.550617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by sending a null value in a PUT request to the session update endpoint. This allows nullifying the session expiry, making the session valid indefinitely and bypassing configured session length policies. This issue has been patched in versions 8.6.69 and 9.7.0-alpha.14.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f6j3-w9v3-cq22</id>
    <title>GHSA-f6j3-w9v3-cq22 — Parse Server has a session field immutability bypass via falsy-value guard</title>
    <updated>2026-10-06T05:02:09.550644+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: parse-server</p>
<p>### Impact</p>
<p>An authenticated user can bypass the immutability guard on session fields (`expiresAt`, `createdWith`) by sending a null value in a PUT request to the session update endpoint. This allows nullifying the session expiry, making the session valid indefinitely and bypassing configured session length policies.</p>
<p>### Patches</p>
<p>The truthiness-based guard checks were replaced with key-presence checks that reject any value for protected session fields, including null.</p>
<p>### Workarounds</p>
<p>There is no known workaround. A `beforeSave` trigger on `_Session` could be used to reject null values for `expiresAt` and `createdWith`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f6j3-w9v3-cq22"/>
  </entry>
</feed>
