GHSA-2cjm-2gwv-m892

Suggest an improvement
Source
https://github.com/advisories/GHSA-2cjm-2gwv-m892
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-2cjm-2gwv-m892/GHSA-2cjm-2gwv-m892.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2cjm-2gwv-m892
Aliases
Published
2026-03-12T17:29:49Z
Modified
2026-03-16T10:41:19.246801Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance
Details

Impact

Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly across all OAuth2 provider configurations. Under concurrent authentication requests for different OAuth2 providers, one provider's token validation may execute using another provider's configuration, potentially allowing a token that should be rejected by one provider to be accepted because it is validated against a different provider's policy.

Deployments that configure multiple OAuth2 providers via the oauth2: true flag are affected.

Patches

The fix ensures that a new adapter instance is created for each provider instead of reusing the singleton, so each provider's configuration is isolated.

Workarounds

There is no known workaround. If only a single OAuth2 provider is configured, the race condition cannot occur.

References

  • GitHub security advisory: https://github.com/parse-community/parse-server/security/advisories/GHSA-2cjm-2gwv-m892
  • Fix Parse Server 9: https://github.com/parse-community/parse-server/releases/tag/9.6.0-alpha.11
  • Fix Parse Server 8: https://github.com/parse-community/parse-server/releases/tag/8.6.37
Database specific
{
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-362"
    ],
    "severity": "CRITICAL",
    "github_reviewed_at": "2026-03-12T17:29:49Z",
    "nvd_published_at": "2026-03-12T19:16:19Z"
}
References

Affected packages

npm / parse-server

Package

Affected ranges

Type
SEMVER
Events
Introduced
9.0.0
Fixed
9.6.0-alpha.11

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-2cjm-2gwv-m892/GHSA-2cjm-2gwv-m892.json"

npm / parse-server

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.6.37

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-2cjm-2gwv-m892/GHSA-2cjm-2gwv-m892.json"