What parse-community/parse-server shipped
Written by FoxPlug from public releases; not affiliated with Parseplatform. An automatic summary of the public release, pull request and commit data of github.com/parse-community/parse-server. Parseplatform did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Version 9.10.1 released with fixes for query explain triggers, LDAP auth account takeover, and dependency updates. Release
- Fixed server crash caused by file pointers without URLs in object writes (GHSA-gpr6-gr9g-pfw6). Pull request #10695
- Fixed LiveQuery evaluating class-level permissions against incomplete caller identity, causing incorrect access denials. Pull request #10675
- Fixed LiveQuery ignoring userField protectedFields groups, causing over-redaction of fields that REST queries return. Pull request #10690
- Fixed in-memory cache adapter ignoring per-entry TTL configuration. Pull request #10671
- Fixed graphQLPublicIntrospection option having no effect on GraphQL introspection queries. Pull request #10696
- Fixed GraphQL schema disclosure via automatic persisted query replay when public introspection is disabled (GHSA-gxxq-pghq-9vrc). Pull request #10670
- Fixed relation count queries bypassing protectedFields for identity-scoped groups (GHSA-rmhf-xv62-rm99). Pull request #10668
- Fixed GraphQL validation errors disclosing target class names when public introspection is disabled (GHSA-6m77-f8xr-f723). Pull request #10666
- Updated @parse/push-adapter to 8.5.3, resolving critical protobufjs vulnerabilities. Pull request #10676
Why it matters
Version 9.10.1 addresses multiple security vulnerabilities in GraphQL introspection, field-level access control, and authentication. LiveQuery fixes ensure permission evaluation matches REST API behavior. Critical dependency updates resolve production vulnerabilities.
Changelog entry
- Bug Fixes: Parse.Query.explain runs afterFind trigger on query plan results; Account takeover via empty password in LDAP auth adapter (GHSA-863r-39r9-vfcf); Dependency updates for @parse/push-adapter, body-parser, and others Release
- Bug Fixes: Server crash via file pointer without URL in an object write (GHSA-gpr6-gr9g-pfw6) Pull request #10695
- Bug Fixes: LiveQuery evaluates class-level permissions against an incomplete caller identity Pull request #10675
- Bug Fixes: LiveQuery ignores userField protectedFields groups and over-redacts fields the REST path returns Pull request #10690
- Bug Fixes: Per-entry cache TTL is ignored by the in-memory cache adapter Pull request #10671
- Bug Fixes: Parse Server option graphQLPublicIntrospection has no effect Pull request #10696
- Bug Fixes: GraphQL schema is disclosed by replaying an automatic persisted query when public introspection is disabled (GHSA-gxxq-pghq-9vrc) Pull request #10670
- Bug Fixes: Relation count query bypasses protectedFields for identity-scoped groups (GHSA-rmhf-xv62-rm99) Pull request #10668
- Bug Fixes: GraphQL argument and enum validation errors disclose target class names when public introspection is disabled (GHSA-6m77-f8xr-f723) Pull request #10666
[16] Parse Server 9.10.1 released: fixes for query explain triggers, LDAP auth, GraphQL introspection disclosures, LiveQuery permissions, and critical dependency updates.
Parse Server 9.10.1 is now available. This release includes fixes for security vulnerabilities in GraphQL introspection and field access control, resolves LiveQuery permission evaluation inconsistencies with the REST API, addresses an LDAP authentication account takeover issue, and updates critical production dependencies including protobufjs.
More from parse-community/parse-server on GitHub
Merged pull requests
- ci: Benchmarks check fails on CI runner noise (#10704, merged September 27, 2026 by mtrezza) (source)
- refactor: Bump graphql from 16.13.2 to 16.14.2 (#10703, merged September 26, 2026 by mtrezza) (source)
- refactor: Bump yaml from 2.9.0 to 2.9.1 (#10698, merged September 26, 2026 by mtrezza) (source)
- refactor: Bump eslint-plugin-expect-type from 0.6.2 to 0.7.0 (#10697, merged September 26, 2026 by mtrezza) (source)
- fix: Parse Server option
graphQLPublicIntrospectionhas no effect (#10696, merged September 26, 2026 by mtrezza) (source) - fix: Server crash via file pointer without URL in an object write (GHSA-gpr6-gr9g-pfw6) (#10695, merged September 25, 2026 by mtrezza) (source)
- fix: Server crash via file pointer without URL in an object write (GHSA-gpr6-gr9g-pfw6) (#10694, merged September 25, 2026 by mtrezza) (source)
- fix: LiveQuery ignores userField protectedFields groups and over-redacts fields the REST path returns (#10690, merged September 24, 2026 by mtrezza) (source)
- fix: LiveQuery evaluates class-level permissions against an incomplete caller identity (#10675, merged September 24, 2026 by mtrezza) (source)
- build: Release (#10689, merged September 24, 2026 by parseplatformorg) (source)
- fix: Bump parse from 8.6.0 to 8.6.2, @parse/push-adapter from 8.5.3 to 8.5.5 and ws from 8.21.0 to 8.21.3 (#10688, merged September 24, 2026 by mtrezza) (source)
- refactor: Bump glob from 10.4.5 to 13.0.6 (#10687, merged September 23, 2026 by mtrezza) (source)