Loading HuntDB...

GHSA-h423-w6qv-2wj3

GitHub Security Advisory

parse-server crashes when receiving file download request with invalid byte range

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact

Parse Server crashes when a file download request is received with an invalid byte range.

### Patches

Improved parsing of the range parameter to properly handle invalid range requests.

### Workarounds

None

### References

- [GHSA-h423-w6qv-2wj3](https://github.com/parse-community/parse-server/security/advisories/GHSA-h423-w6qv-2wj3)

Affected Packages

npm parse-server
Affected versions: 0 (fixed in 4.10.17)
npm parse-server
Affected versions: 5.0.0 (fixed in 5.2.8)

Related CVEs

Key Information

GHSA ID
GHSA-h423-w6qv-2wj3
Published
October 18, 2022 4:08 PM
Last Modified
October 18, 2022 4:08 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
parse-server
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.