{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-105828", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-10-05T21:59:09.591Z", "datePublished": "2026-10-08T14:10:29.996Z", "dateUpdated": "2026-10-08T18:11:39.339Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-10-08T14:10:29.996Z" }, "datePublic": "2026-09-21T00:00:00.000Z", "title": "Parse Server 9.0.0 before 9.10.1-alpha.12 Class Name Disclosure via GraphQL Errors", "descriptions": [ { "lang": "en", "value": "Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public introspection is disabled. Unauthenticated attackers holding only the public Application Id can send crafted operations triggering unknown-argument or invalid enum value errors to learn pointer and relation target classes." } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Generation of Error Message Containing Sensitive Information", "cweId": "CWE-209", "type": "CWE" } ] } ], "affected": [ { "vendor": "parse-community", "product": "parse-server", "defaultStatus": "unaffected", "packageURL": "pkg:npm/parse-server", "versions": [ { "version": "9.0.0", "status": "affected", "versionType": "semver", "lessThan": "9.10.1-alpha.12" }, { "version": "9.10.1-alpha.12", "status": "unaffected", "versionType": "semver" } ] }, { "vendor": "parse-community", "product": "parse-server", "defaultStatus": "unaffected", "packageURL": "pkg:npm/parse-server", "versions": [ { "version": "8.2.2", "status": "affected", "versionType": "semver", "lessThan": "8.6.92" }, { "version": "8.6.92", "status": "unaffected", "versionType": "semver" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:*:*:*", "versionStartIncluding": "9.0.0", "versionEndExcluding": "9.10.1-alpha.12" }, { "vulnerable": true, "criteria": "cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:*:*:*", "versionStartIncluding": "8.2.2", "versionEndExcluding": "8.6.92" } ] } ] } ], "metrics": [ { "format": "CVSS", "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "PRESENT", "privilegesRequired": "NONE", "userInteraction": "NONE", "vulnConfidentialityImpact": "LOW", "vulnIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "baseScore": 6.3, "baseSeverity": "MEDIUM" } } ], "references": [ { "url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-6m77-f8xr-f723", "tags": [ "vendor-advisory" ], "name": "GitHub Security Advisory (GHSA-6m77-f8xr-f723)" }, { "name": "VulnCheck Advisory: Parse Server 9.0.0 before 9.10.1-alpha.12 Class Name Disclosure via GraphQL Errors", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/parse-server-9.0.0-before-9.10.1-alpha.12-class-name-disclosure-via-graphql-errors" } ], "credits": [ { "lang": "en", "value": "arpitjain099", "type": "reporter" }, { "lang": "en", "value": "mtrezza", "type": "coordinator" } ], "x_generator": { "engine": "vulncheck-endgame" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-08T18:11:32.734902Z", "id": "CVE-2026-105828", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-08T18:11:39.339Z" } } ] } }