Launch Week Day 1: Announcing Security Design Review
UNKNOWN npm

Parse Server crash via deeply nested query condition operators

GHSA-9xp9-j92r-p88v · BIT-parse-2026-32944 · CVE-2026-32944

Published · Modified

Description

Impact

An unauthenticated attacker can crash the Parse Server process by sending a single request with deeply nested query condition operators. This terminates the server and denies service to all connected clients.

Patches

A depth limit for query condition operator nesting has been added via the requestComplexity.queryDepth server option. The option is disabled by default to avoid a breaking change. To mitigate, upgrade and set the option to a value appropriate for your app.

Workarounds

None.

Ready to move

Start Securing

Free, no credit card | First findings in minutes