#VU124998 Observable Response Discrepancy in Parse Server - CVE-2026-31901
Published: April 6, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to observable response discrepancy in the /verificationEmailRequest endpoint when handling email verification requests. A remote attacker can send requests with different email addresses and observe distinct error responses to disclose sensitive information.
Only deployments with email verification enabled (verifyUserEmails: true) are vulnerable.