GHSA-h423-w6qv-2wj3
GitHub Security Advisory
parse-server crashes when receiving file download request with invalid byte range
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
### Impact
Parse Server crashes when a file download request is received with an invalid byte range.
### Patches
Improved parsing of the range parameter to properly handle invalid range requests.
### Workarounds
None
### References
- [GHSA-h423-w6qv-2wj3](https://github.com/parse-community/parse-server/security/advisories/GHSA-h423-w6qv-2wj3)
Affected Packages
npm
parse-server
Affected versions:
0
(fixed in 4.10.17)
npm
parse-server
Affected versions:
5.0.0
(fixed in 5.2.8)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.