Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its validators on storage adapters that support streaming (e.g. the default GridFS adapter). This allows access to files that should be protected by afterFind trigger authorization logic or built-in validators such as requireUser. This issue has been patched in versions 8.6.71 and 9.7.1-alpha.1. | |
| Title | Parse Server: Streaming file download bypasses afterFind file trigger authorization | |
| Weaknesses | CWE-285 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-31T20:29:38.765Z
Reserved: 2026-03-30T19:54:55.556Z
Link: CVE-2026-34784
Updated: 2026-03-31T20:29:34.734Z
Status : Received
Published: 2026-03-31T20:16:29.490
Modified: 2026-03-31T20:16:29.490
Link: CVE-2026-34784
No data.
OpenCVE Enrichment
No data.