8.6.98
8.6.98 (2026-10-04) Bug Fixes Session creation endpoint bypasses create and addField class-level permissions (GHSA-gj37-5hg5-p729) (#10745) (019b4a4)
8.6.98 (2026-10-04) Bug Fixes Session creation endpoint bypasses create and addField class-level permissions (GHSA-gj37-5hg5-p729) (#10745) (019b4a4)
9.10.3-alpha.1 (2026-10-04) Bug Fixes Session creation endpoint bypasses create and addField class-level permissions (GHSA-gj37-5hg5-p729) (#10744) (ef08e80)
9.10.2 (2026-10-02) Bug Fixes Create and update class-level permissions not enforced before schema validation (#10739) (27a15e1) LiveQuery evaluates class-level permissions against an incomplete caller identity (#10675) (6bf4bd9) LiveQuery ignores Parse Server option protectedFieldsOwnerExempt (#10737) (8d2dd8c) LiveQuery ignores userField protectedFields groups and over-redacts fields the REST pa…
9.10.2-alpha.9 (2026-10-02) Bug Fixes Create and update class-level permissions not enforced before schema validation (#10739) (27a15e1)
9.10.2-alpha.8 (2026-10-02) Bug Fixes Rate limit with option requestPath set to GraphQL endpoint path has no effect (#10738) (c23825e)
9.10.2-alpha.7 (2026-10-02) Bug Fixes LiveQuery ignores Parse Server option protectedFieldsOwnerExempt (#10737) (8d2dd8c)
8.6.97 (2026-09-30) Bug Fixes Server crash via unhandled error when sending verification or password reset email (GHSA-46jj-qw3p-48fc) (#10731) (090ff7f)
9.10.2-alpha.6 (2026-09-30) Bug Fixes Server crash via unhandled error when sending verification or password reset email ((GHSA-46jj-qw3p-48fc)) (#10730) (0893540)
8.6.96 (2026-09-28) Bug Fixes Transactional batch request can roll back or block writes of other clients (GHSA-jhh9-hrgh-c9gv) (#10716) (c21ad8c), closes GHSA-jhh9-hr#c9 /github.com/parse-community/parse-server/security/advisories/GHSA-jhh9-hr#c9
9.10.2-alpha.5 (2026-09-28) Bug Fixes Transactional batch request can roll back or block writes of other clients (GHSA-jhh9-hrgh-c9gv) (#10713) (90b6c9d), closes GHSA-jhh9-hr#c9 /github.com/parse-community/parse-server/security/advisories/GHSA-jhh9-hr#c9
9.10.2-alpha.4 (2026-09-26) Bug Fixes Parse Server option graphQLPublicIntrospection has no effect (#10696) (1ce39d4)
8.6.95 (2026-09-25) Bug Fixes Server crash via file pointer without URL in an object write (GHSA-gpr6-gr9g-pfw6) (#10695) (726b1ea)
9.10.2-alpha.3 (2026-09-25) Bug Fixes Server crash via file pointer without URL in an object write (GHSA-gpr6-gr9g-pfw6) (#10694) (d77cd86)
9.10.2-alpha.2 (2026-09-24) Bug Fixes LiveQuery ignores userField protectedFields groups and over-redacts fields the REST path returns (#10690) (e8b3c92)
9.10.2-alpha.1 (2026-09-24) Bug Fixes LiveQuery evaluates class-level permissions against an incomplete caller identity (#10675) (6bf4bd9)
9.10.1 (2026-09-24) Bug Fixes Parse.Query.explain runs afterFind trigger on query plan results (#10536) (64d58ff) Account takeover via empty password in LDAP auth adapter (GHSA-863r-39r9-vfcf) (#10642) (f261957) Bump @parse/push-adapter from 8.4.0 to 8.5.3 (#10676) (ae167c4) Bump body-parser from 2.2.2 to 2.3.0 (#10600) (77e955f) Bump express-rate-limit from 8.3.1 to 8.7.0 (#10672) (73d8600) Bump…
9.10.1-alpha.21 (2026-09-24) Bug Fixes Bump parse from 8.6.0 to 8.6.2, @parse/push-adapter from 8.5.3 to 8.5.5 and ws from 8.21.0 to 8.21.3 (#10688) (11c8a40)
9.10.1-alpha.20 (2026-09-23) Bug Fixes Bump body-parser from 2.2.2 to 2.3.0 (#10600) (77e955f)
9.10.1-alpha.19 (2026-09-23) Bug Fixes Bump qs from 6.15.2 to 6.16.0 (#10651) (25263e7)
9.10.1-alpha.18 (2026-09-23) Bug Fixes Bump undici from 7.28.0 to 7.29.1 (#10674) (2f09a30)
9.10.1-alpha.17 (2026-09-23) Bug Fixes Bump @parse/push-adapter from 8.4.0 to 8.5.3 (#10676) (ae167c4)
9.10.1-alpha.16 (2026-09-22) Bug Fixes Per-entry cache TTL is ignored by the in-memory cache adapter (#10671) (1352c67)
9.10.1-alpha.15 (2026-09-22) Bug Fixes Bump express-rate-limit from 8.3.1 to 8.7.0 (#10672) (73d8600)
8.6.94 (2026-09-22) Bug Fixes GraphQL schema is disclosed by replaying an automatic persisted query when public introspection is disabled (GHSA-gxxq-pghq-9vrc) (#10670) (c2e613a)
9.10.1-alpha.14 (2026-09-22) Bug Fixes GraphQL schema is disclosed by replaying an automatic persisted query when public introspection is disabled (GHSA-gxxq-pghq-9vrc) (#10669) (8d22053)
8.6.93 (2026-09-22) Bug Fixes Relation count query bypasses protectedFields for identity-scoped groups (GHSA-rmhf-xv62-rm99) (#10668) (d17586b)
9.10.1-alpha.13 (2026-09-22) Bug Fixes Relation count query bypasses protectedFields for identity-scoped groups (GHSA-rmhf-xv62-rm99) (#10667) (a32977f)
8.6.92 (2026-09-21) Bug Fixes GraphQL argument and enum validation errors disclose target class names when public introspection is disabled (GHSA-6m77-f8xr-f723) (#10666) (1cd1f8f)
9.10.1-alpha.12 (2026-09-21) Bug Fixes GraphQL argument and enum validation errors disclose target class names when public introspection is disabled (GHSA-6m77-f8xr-f723) (#10665) (fead3db)
9.10.1-alpha.11 (2026-09-13) Bug Fixes Rate limit is bypassed by sending request header X-Forwarded-For: 127.0.0.1 when Parse Server option trustProxy is permissive (#10664) (ebd425e)