Executive brief
Parse Server is a popular backend framework that provides APIs for user authentication and data management. The email verification resend feature returns different responses based on whether a username exists in the system, allowing attackers to enumerate valid user accounts without authentication. This information disclosure could enable targeted attacks against known accounts.
Technical details
The vulnerability is an information disclosure (CWE-204) in Parse Server's email verification resend routes (both Pages and legacy PublicAPI). When a user requests to resend a verification email, the routes return distinguishable responses (different redirect targets) depending on whether the provided username exists and has an unverified email. An unauthenticated attacker can observe these response differences to enumerate valid usernames. The existing emailVerifySuccessOnInvalidEmail configuration option, enabled by default, protected the API route but did not apply to these specific resend routes. The fix applies the configuration option uniformly across all routes, making them return the same success page regardless of outcome.
Affected products
- Parse Community Parse Server < 8.6.51 and >= 9.0.0, < 9.6.0-alpha.40
Timeline
- 2026-03-19: disclosed