Vulnerabilities
CVE-2026-30854 - Parse Server: GraphQL `__type` introspection bypass via inline fragments when pu...
CVE ID :CVE-2026-30854 Published : March 7, 2026, 4:24 p.m. | 54 minutes ago Description :Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3.1-alpha.3 to before version 9.5.0-alpha.10, when graphQLPublicIntrospection is disabled, __type queries nested inside inline fragments (e.g. ... on Query { __type(name: