#VU124980 Protection Mechanism Failure in Parse Server - CVE-2026-30938
Published: April 6, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote attacker to bypass a keyword denylist protection.
The vulnerability exists due to protection mechanism failure in the requestKeywordDenylist keyword scanner when processing request payloads containing a nested object or array before a prohibited keyword. A remote attacker can send a specially crafted request payload to bypass a keyword denylist protection.
The requestKeywordDenylist security control is enabled by default, and custom denylist entries configured by the developer are affected as well.