Information Exposure Through an Error Message in Parse Server - CVE-2026-30835

 

Information Exposure Through an Error Message in Parse Server - CVE-2026-30835

Published: April 6, 2026


Vulnerability identifier: #VU124971
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-30835
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to generation of error messages containing sensitive information in the query execution layer when processing malformed $regex query parameters. A remote attacker can send a specially crafted query request to disclose sensitive information.

The issue leaks database internals such as error messages, error codes, code names, cluster timestamps, and topology details.


Affected software

Parse Server

How to mitigate CVE-2026-30835

Install security update from vendor's website.

Parse Server - addressed in versions 8.6.7, 9.5.0 alpha.6

External References

Related Security Bulletins