Repository navigation
Releases: parse-community/parse-server
Releases · parse-community/parse-server
Release list
9.10.5-alpha.1
9.10.4
9.10.4 (2026-10-09)
Bug Fixes
- Batch and direct access requests fail for object IDs without alphanumeric characters or class names without letters (#10761) (c8d5ebb)
- GraphQL API fails when a class name or mutation alias collides with a built-in name (#10757) (866e82b)
- Object write with a reserved field name can make reads fail on MongoDB (GHSA-gwrq-q25v-g8mr) (#10763) (d90b841)
- Unauthenticated deletion of class schemas removes class-level permissions on MongoDB (GHSA-qmg9-m772-5rm7) (#10767) (2114fca)
9.10.4-alpha.4
9.10.4-alpha.4 (2026-10-08)
Bug Fixes
- Unauthenticated deletion of class schemas removes class-level permissions on MongoDB (GHSA-qmg9-m772-5rm7) (#10767) (2114fca)
9.10.4-alpha.3
9.10.4-alpha.3 (2026-10-08)
Bug Fixes
- Object write with a reserved field name can make reads fail on MongoDB (GHSA-gwrq-q25v-g8mr) (#10763) (d90b841)
8.6.101
8.6.101 (2026-10-08)
Bug Fixes
- Unauthenticated deletion of class schemas removes class-level permissions on MongoDB (GHSA-qmg9-m772-5rm7) (#10768) (2f3e236)
8.6.100
8.6.100 (2026-10-08)
Bug Fixes
- Object write with a reserved field name can make reads fail on MongoDB (GHSA-gwrq-q25v-g8mr) (#10764) (9133478)
9.10.4-alpha.2
9.10.4-alpha.1
9.10.3
9.10.3 (2026-10-05)
Bug Fixes
- Session creation endpoint bypasses create and addField class-level permissions (GHSA-gj37-5hg5-p729) (#10744) (ef08e80)
- User update accepts an empty username or password (#10752) (99444cf)
- User update runs checks against the target account before authorization (GHSA-p49q-9w65-f9p7) (#10746) (643b918)