CVE-2026-31828 | parse-community parse-server up to 8.6.25/9.5.2-alpha.12 ldap injection (GHSA-7m6r-fhh7-r47c)
A vulnerability classified as critical was found in parse-community parse-server up to 8.6.25/9.5.2-alpha.12. Impacted is an unknown function. Such manipulation leads to ldap injection.
This vulnerability is listed as CVE-2026-31828. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.