9.10.1-alpha.11
9.10.1-alpha.11 (2026-09-13) Bug Fixes Rate limit is bypassed by sending request header X-Forwarded-For: 127.0.0.1 when Parse Server option trustProxy is permissive (#10664) (ebd425e)
9.10.1-alpha.11 (2026-09-13) Bug Fixes Rate limit is bypassed by sending request header X-Forwarded-For: 127.0.0.1 when Parse Server option trustProxy is permissive (#10664) (ebd425e)
8.6.91 (2026-09-13) Bug Fixes Unverified auth provider identity accepted on password login for code-based auth adapters (GHSA-mr43-w6c2-mvjq) (#10663) (85f5dc0)
9.10.1-alpha.10 (2026-09-13) Bug Fixes Unverified auth provider identity accepted on password login for code-based auth adapters (GHSA-mr43-w6c2-mvjq) (#10662) (9b73e6f)
8.6.90 (2026-09-09) Bug Fixes Unauthenticated deletion of installation records via operator injection in device token deduplication (GHSA-cc6h-c8m4-hgrx) (#10658) (2a60732)
9.10.1-alpha.9 (2026-09-09) Bug Fixes Unauthenticated deletion of installation records via operator injection in device token deduplication (GHSA-cc6h-c8m4-hgrx) (#10657) (ad00f82)
8.6.89 (2026-09-08) Bug Fixes LiveQuery discloses protected fields by resolving an incomplete subscriber identity (GHSA-9jpp-xhh6-75mf) (#10655) (e87b228)
9.10.1-alpha.8 (2026-09-08) Bug Fixes LiveQuery discloses protected fields by resolving an incomplete subscriber identity (GHSA-9jpp-xhh6-75mf) (#10654) (66c507b)
8.6.88 (2026-08-25) Bug Fixes Account takeover via empty password in LDAP auth adapter (GHSA-863r-39r9-vfcf) (#10644) (4e19721)
9.10.1-alpha.7 (2026-08-25) Bug Fixes Account takeover via empty password in LDAP auth adapter (GHSA-863r-39r9-vfcf) (#10642) (f261957)
9.10.1-alpha.6 (2026-07-26) Bug Fixes Parse.Query.explain runs afterFind trigger on query plan results (#10536) (64d58ff)
9.10.1-alpha.5 (2026-07-25) Bug Fixes Server crash from unhandled promise rejection when multiple Cloud Code validator fields fail (#10540) (90c2778)
9.10.1-alpha.4 (2026-07-24) Bug Fixes Install the latest Parse Server version in bootstrap.sh (#10556) (997ee15)
9.10.1-alpha.3 (2026-07-16) Bug Fixes Bump ws from 8.20.0 to 8.21.0 (#10576) (629426f)
9.10.1-alpha.2 (2026-07-14) Bug Fixes Creating a session can delete another user's session (#10582) (0df8779)
9.10.1-alpha.1 (2026-07-13) Bug Fixes Bump follow-redirects from 1.15.11 to 1.16.0 (#10577) (d577327)
9.10.0 (2026-07-13) Bug Fixes Cloud Code beforeFind trigger context is not isolated from prototype pollution (#10570) (bea001e) Cloud Function multipart requests bypass the maxUploadSize limit (#10498) (f12e1c3) Denial of service via exponential-time processing of deeply nested query operators (GHSA-cgxm-vr2f-6fj8) (#10511) (1103c7a) Endpoints /login and /verifyPassword disclose MFA secrets and pr…
9.10.0-alpha.8 (2026-07-13) Bug Fixes GeoPoint distance queries fail with an internal server error on MongoDB 8.3 and later (#10572) (b706c22)
9.10.0-alpha.7 (2026-07-11) Bug Fixes Cloud Code beforeFind trigger context is not isolated from prototype pollution (#10570) (bea001e)
8.6.87 (2026-07-10) Bug Fixes GraphQL error messages disclose pointer and relation target class names when public introspection is disabled (GHSA-r2g6-4f6j-f6rf) (#10569) (bc863d7)
9.10.0-alpha.6 (2026-07-10) Bug Fixes GraphQL error messages disclose pointer and relation target class names when public introspection is disabled (GHSA-r2g6-4f6j-f6rf) (#10568) (cb9b542)
8.6.86 (2026-07-10) Bug Fixes GraphQL error messages disclose required input field names when public introspection is disabled (GHSA-2fgh-8j2g-w354) (#10567) (6985a38), closes GHSA-2f#8j2g-w354 /github.com/parse-community/parse-server/security/advisories/GHSA-2f#8j2g-w354
9.10.0-alpha.5 (2026-07-10) Bug Fixes GraphQL error messages disclose required input field names when public introspection is disabled (GHSA-2fgh-8j2g-w354) (#10566) (d96c945), closes GHSA-2f#8j2g-w354 /github.com/parse-community/parse-server/security/advisories/GHSA-2f#8j2g-w354
8.6.85 (2026-07-08) Bug Fixes GraphQL variable-coercion suggestions disclose schema to unauthenticated callers (GHSA-9g8f-h8f3-hjcm) (#10564) (2728fcb)
9.10.0-alpha.4 (2026-07-07) Bug Fixes GraphQL variable-coercion suggestions disclose schema to unauthenticated callers (GHSA-9g8f-h8f3-hjcm) (#10563) (2625489)
9.10.0-alpha.3 (2026-07-07) Bug Fixes NumberOrBoolean config option (cluster) value not coerced from env/CLI (#10531) (459786f)
8.6.84 (2026-06-25) Bug Fixes Stored XSS via malformed Content-Type bypassing file upload extension blocklist (GHSA-r899-h629-j84r) (#10523) (55eab32)
9.10.0-alpha.2 (2026-06-25) Bug Fixes Stored XSS via malformed Content-Type bypassing file upload extension blocklist (GHSA-r899-h629-j84r) (#10521) (cce91e5)
9.10.0-alpha.1 (2026-06-19) Features Add option to disallow aggregation pipelines for the read-only master key (#10517) (816078f)
8.6.83 (2026-06-19) Bug Fixes LiveQuery discloses object data to a subscriber across an ACL read-access change (GHSA-97pr-9hgg-3p8r) (#10516) (c9b24ce)
9.9.1-alpha.13 (2026-06-19) Bug Fixes LiveQuery discloses object data to a subscriber across an ACL read-access change (GHSA-97pr-9hgg-3p8r) (#10515) (e9c85df)