CVE-2026-31901: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-31901 is a user enumeration vulnerability in Parse Server (npm package by parse-community) affecting the email verification endpoint (/verificationEmailRequest). The endpoint returns distinct error responses depending on whether an email address belongs to an existing user, is already verified, or does not exist — allowing unauthenticated attackers to enumerate registered email addresses. It affects all Parse Server versions below 8.6.34 and versions 9.0.0 through below 9.6.0-alpha.8, and only impacts deployments with email verification enabled (verifyUserEmails: true). The vulnerability was published on March 10, 2026, with a CVSS v3.1 score of 5.3 (Medium) and a CVSS v4.0 score of 6.3 (Medium) (Github Advisory, Parse Server Advisory).

Technical details

The root cause is classified as CWE-204 (Observable Response Discrepancy): the /verificationEmailRequest endpoint leaks internal application state by returning different HTTP error codes or response bodies depending on whether the submitted email address is unregistered, registered but unverified, or already verified. An unauthenticated remote attacker can exploit this by sending automated HTTP requests with different email addresses and observing the response codes to determine which addresses are registered in the system. No authentication, special privileges, or user interaction is required; the only precondition is that the target Parse Server instance has verifyUserEmails: true configured. The vulnerability was reported by researcher 0xkakash1 and analyzed by mtrezza (Parse Server Advisory, Github Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to enumerate valid email addresses registered in the application, resulting in a low confidentiality impact with no integrity or availability impact. The disclosed information (confirmed registered email addresses) can be leveraged for downstream attacks such as targeted phishing, credential stuffing, or brute-force login attempts against identified accounts. The vulnerability's scope is limited to Parse Server deployments with email verification enabled, and there is no evidence of lateral movement or direct data exfiltration beyond user account enumeration (Parse Server Advisory).

Exploitability

No public proof-of-concept exploit code or exploit kits have been identified for this vulnerability. There is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.044% (14th percentile), indicating a low near-term exploitation probability (Github Advisory). No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Parse Server instances (e.g., via Shodan, Censys, or application fingerprinting) running versions below 8.6.34 or between 9.0.0 and 9.6.0-alpha.8 with verifyUserEmails: true enabled.
  2. Prepare email list: Compile a list of candidate email addresses to test (e.g., from public sources, data breach dumps, or common patterns for the target organization).
  3. Send enumeration requests: For each candidate email, send an HTTP POST request to the /verificationEmailRequest endpoint of the Parse Server instance:
    POST /verificationEmailRequest HTTP/1.1
    Host: <target-parse-server>
    Content-Type: application/json
    
    {"email": "candidate@example.com"}
  4. Analyze responses: Observe the distinct error codes or response bodies returned — different responses indicate whether the email is unregistered, registered but unverified, or already verified.
  5. Build user list: Compile confirmed registered email addresses based on the response discrepancies for use in follow-on attacks such as phishing or credential stuffing (Parse Server Advisory).

Indicators of compromise

  • Network: High volume of HTTP POST requests to /verificationEmailRequest from a single IP or a distributed set of IPs, especially with many different email addresses in a short time window.
  • Logs: Parse Server access logs showing repeated requests to /verificationEmailRequest with varying email parameters and differing response codes (e.g., 400, 404, 200) across requests from the same source.
  • Behavioral: Automated or scripted request patterns (consistent timing intervals, sequential or dictionary-based email address submissions) targeting the email verification endpoint.

Mitigation and workarounds

Parse Server has released patched versions 8.6.34 (for the 8.x branch) and 9.6.0-alpha.8 (for the 9.x alpha branch), both published on March 10, 2026. The fix introduces a new server option emailVerifySuccessOnInvalidEmail (default: true) that returns a generic success response for all verification email requests regardless of the email's registration status, preventing response-based enumeration. The patch also strengthens input validation for the related resetPasswordSuccessOnInvalidEmail option and adds security warnings when either enumeration mitigation is disabled. There is no known workaround — upgrading to a patched version is the only remediation (Parse Server Advisory, Release 8.6.34, Release 9.6.0-alpha.8).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management