CVE-2026-35200
Last modified
CVE-2026-35200 is a low-severity vulnerability rated 2.1/10 on the CVSS scale. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .txt) but with a Content-Type header that differs from the extension (e.g., text/html). EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .txt) but with a Content-Type header that differs from the extension (e.g., text/html). The Content-Type is passed to the storage adapter without consistency validation. Storage adapters that store and serve the provided Content-Type (such as S3 or GCS) serve the file with the mismatched Content-Type. The default GridFS adapter is not affected because it derives Content-Type from the filename at serving time. This vulnerability is fixed in 8.6.73 and 9.7.1-alpha.4.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Parseplatform | Parse-Server | < 8.6.73 | — |
| Parseplatform | Parse-Server | >= 9.0.0, < 9.7.1 | — |
| Parseplatform | Parse-Server | 9.7.1 | Alpha1 |
References
- https://github.com/parse-community/parse-server/pull/10383Issue Tracking, Patch
- https://github.com/parse-community/parse-server/pull/10384Issue Tracking, Patch
- https://github.com/parse-community/parse-server/security/advisories/GHSA-vr5f-2r24-w5hcMitigation, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-35200?
How severe is CVE-2026-35200?
How do I fix CVE-2026-35200?
Are you affected by CVE-2026-35200?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
