9.10.2 (2026-10-02)
Bug Fixes
- Create and update class-level permissions not enforced before schema validation (#10739) (27a15e1)
- LiveQuery evaluates class-level permissions against an incomplete caller identity (#10675) (6bf4bd9)
- LiveQuery ignores Parse Server option
protectedFieldsOwnerExempt(#10737) (8d2dd8c) - LiveQuery ignores userField protectedFields groups and over-redacts fields the REST path returns (#10690) (e8b3c92)
- Parse Server option
graphQLPublicIntrospectionhas no effect (#10696) (1ce39d4) - Rate limit with option
requestPathset to GraphQL endpoint path has no effect (#10738) (c23825e) - Server crash via file pointer without URL in an object write (GHSA-gpr6-gr9g-pfw6) (#10694) (d77cd86)
- Server crash via unhandled error when sending verification or password reset email ((GHSA-46jj-qw3p-48fc)) (#10730) (0893540)
- Transactional batch request can roll back or block writes of other clients (GHSA-jhh9-hrgh-c9gv) (#10713) (90b6c9d), closes GHSA-jhh9-hr#c9 /github.com/parse-community/parse-server/security/advisories/GHSA-jhh9-hr#c9