<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T21:11:33.713608+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-parse-2026-39321</id>
    <title>BIT-parse-2026-39321 — Parse Server has a login timing side-channel reveals user existence</title>
    <updated>2026-10-08T21:11:33.774984+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: parse</p>
<p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0 and 8.6.74, he login endpoint response time differs measurably depending on whether the submitted username or email exists in the database. When a user is not found, the server responds immediately. When a user exists but the password is wrong, a bcrypt comparison runs first, adding significant latency. This timing difference allows an unauthenticated attacker to enumerate valid usernames. This vulnerability is fixed in 9.8.0 and 8.6.74.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-parse-2026-39321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-281156</id>
    <title>EUVD-2026-281156</title>
    <updated>2026-10-08T21:11:33.775063+00:00</updated>
    <content>EUVD-2026-281156</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-281156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39321</id>
    <title>fkie_cve-2026-39321</title>
    <updated>2026-10-08T21:11:33.775086+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.6 and 8.6.74, he login endpoint response time differs measurably depending on whether the submitted username or email exists in the database. When a user is not found, the server responds immediately. When a user exists but the password is wrong, a bcrypt comparison runs first, adding significant latency. This timing difference allows an unauthenticated attacker to enumerate valid usernames. This vulnerability is fixed in 9.8.0-alpha.6 and 8.6.74.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mmpq-5hcv-hf2v</id>
    <title>GHSA-mmpq-5hcv-hf2v — Parse Server has a login timing side-channel reveals user existence</title>
    <updated>2026-10-08T21:11:33.775129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: parse-server</p>
<p>### Impact</p>
<p>The login endpoint response time differs measurably depending on whether the submitted username or email exists in the database. When a user is not found, the server responds immediately. When a user exists but the password is wrong, a bcrypt comparison runs first, adding significant latency. This timing difference allows an unauthenticated attacker to enumerate valid usernames.</p>
<p>### Patches</p>
<p>A dummy bcrypt comparison is now performed when no user is found, normalizing response timing regardless of user existence. Additionally, accounts without a stored password (e.g. OAuth-only) now also run a dummy comparison to prevent the same timing oracle.</p>
<p>### Workarounds</p>
<p>Configure rate limiting on the login endpoint to slow automated enumeration. This reduces throughput but does not eliminate the timing signal for individual requests.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mmpq-5hcv-hf2v"/>
  </entry>
</feed>
