<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 17:34:57 +0000</lastBuildDate>
    <item>
      <title>BIT-parse-2026-57481 — Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change</title>
      <link>https://cve.radiocsirt.org/vuln/bit-parse-2026-57481</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: parse&lt;/p&gt;
&lt;p&gt;Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber&amp;#39;s ACL read access, because leave and enter events included the wrong object state. This issue is fixed in versions 9.9.1 and 8.6.83.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: parse&lt;/p&gt;
&lt;p&gt;Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber&amp;#39;s ACL read access, because leave and enter events included the wrong object state. This issue is fixed in versions 9.9.1 and 8.6.83.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-parse-2026-57481</guid>
    </item>
    <item>
      <title>EUVD-2026-335585</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335585</link>
      <description>EUVD-2026-335585</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335585</guid>
    </item>
    <item>
      <title>fkie_cve-2026-57481</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57481</link>
      <description>&lt;p&gt;Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber&amp;#39;s ACL read access, because leave and enter events included the wrong object state. This issue is fixed in versions 9.9.1-alpha.13 and 8.6.83.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber&amp;#39;s ACL read access, because leave and enter events included the wrong object state. This issue is fixed in versions 9.9.1-alpha.13 and 8.6.83.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-57481</guid>
    </item>
    <item>
      <title>GHSA-97pr-9hgg-3p8r — parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-97pr-9hgg-3p8r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: parse-server&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A Parse Server LiveQuery subscriber can receive object field values they are not authorized to read when a single `save` changes both an object field and the subscriber&amp;#39;s ACL read access to that object. When such a save removes the subscriber&amp;#39;s read access, the resulting `leave` event still carries the post-update object body, disclosing the new field values the subscriber is no longer permitted to read. The symmetric case applies to the `enter` event: when a save grants read access, the event includes the pre-grant object state the subscriber was not previously permitted to read. The disclosure is bounded to the single object affected by that save and is delivered only to the subscriber whose access changed. Applications that combine content changes with access-control changes in the same save on LiveQuery-enabled classes are affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Parse Server now verifies the subscriber&amp;#39;s authorization for the specific object state included in `leave` and `enter` events. For a `leave` caused by the subscriber losing read access, the event delivers the last object state the subscriber was authorized to see instead of the post-update body. For an `enter` caused by the subscriber gaining read access, the previously unauthorized original object state is omitted. Events caused by a normal query-match change, where the subscriber keeps read access, are unaffected, as are master-key subscribers.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Do not change an object&amp;#39;s field values and a subscrib…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: parse-server&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A Parse Server LiveQuery subscriber can receive object field values they are not authorized to read when a single `save` changes both an object field and the subscriber&amp;#39;s ACL read access to that object. When such a save removes the subscriber&amp;#39;s read access, the resulting `leave` event still carries the post-update object body, disclosing the new field values the subscriber is no longer permitted to read. The symmetric case applies to the `enter` event: when a save grants read access, the event includes the pre-grant object state the subscriber was not previously permitted to read. The disclosure is bounded to the single object affected by that save and is delivered only to the subscriber whose access changed. Applications that combine content changes with access-control changes in the same save on LiveQuery-enabled classes are affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Parse Server now verifies the subscriber&amp;#39;s authorization for the specific object state included in `leave` and `enter` events. For a `leave` caused by the subscriber losing read access, the event delivers the last object state the subscriber was authorized to see instead of the post-update body. For an `enter` caused by the subscriber gaining read access, the previously unauthorized original object state is omitted. Events caused by a normal query-match change, where the subscriber keeps read access, are unaffected, as are master-key subscribers.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Do not change an object&amp;#39;s field values and a subscrib…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-97pr-9hgg-3p8r</guid>
    </item>
  </channel>
</rss>
