Loading HuntDB...

GHSA-xw6g-jjvf-wwf9

GitHub Security Advisory

Invalid file request can crash server

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact
Certain types of invalid files requests are not handled properly and can crash the server. If you are running multiple Parse Server instances in a cluster, the availability impact may be low; if you are running Parse Server as a single instance without redundancy, the availability impact may be high.

### Patches
To prevent this, invalid requests are now properly handled.

### Workarounds
None

### References
- https://github.com/parse-community/parse-server/security/advisories/GHSA-xw6g-jjvf-wwf9
- https://github.com/parse-community/parse-server

### For more information
- For questions or comments about this vulnerability visit our [community forum](http://community.parseplatform.org/) or [community chat](http://chat.parseplatform.org/)
- Report other vulnerabilities at [report.parseplatform.org](https://report.parseplatform.org/)

Affected Packages

npm parse-server
Affected versions: 0 (fixed in 4.10.12)
npm parse-server
Affected versions: 5.0.0 (fixed in 5.2.3)

Related CVEs

Key Information

GHSA ID
GHSA-xw6g-jjvf-wwf9
Published
June 20, 2022 10:25 PM
Last Modified
June 20, 2022 10:25 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
parse-server
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.