Parse Server Password Reset Token Single-Use Bypass Vulnerability

Vulnerability

A vulnerability in Parse Server's password reset mechanism allows tokens to be reused across multiple concurrent requests, prior to versions 9.6.0-alpha.28 and 8.6.48. This flaw enables an attacker who intercepts a reset token to exploit the situation by racing against the legitimate user's request, potentially leading to unauthorized password changes. All Parse Server deployments utilizing the password reset feature are affected.

Impact

Exploitation of this vulnerability allows for a password reset token to be reused, potentially leading to unauthorized password changes.

Remediation

Users can upgrade to Parse Server versions 9.6.0-alpha.28 or 8.6.48, where this vulnerability has been patched.

Added: Mar 18, 2026, 10:24 PM
Updated: Mar 18, 2026, 10:24 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
5.0
exploitability
4.2
remediation
7.7
relevance
4.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.