UNKNOWN npm
Parse Server crash via deeply nested query condition operators
GHSA-9xp9-j92r-p88v · BIT-parse-2026-32944 · CVE-2026-32944
Published · Modified
Description
Impact
An unauthenticated attacker can crash the Parse Server process by sending a single request with deeply nested query condition operators. This terminates the server and denies service to all connected clients.
Patches
A depth limit for query condition operator nesting has been added via the requestComplexity.queryDepth server option. The option is disabled by default to avoid a breaking change. To mitigate, upgrade and set the option to a value appropriate for your app.
Workarounds
None.
References
- WEB https://github.com/parse-community/parse-server/security/advisories/GHSA-9xp9-j92r-p88v
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-32944
- WEB https://github.com/parse-community/parse-server/pull/10202
- WEB https://github.com/parse-community/parse-server/pull/10203
- PACKAGE https://github.com/parse-community/parse-server
Ready to move
Start Securing
Free, no credit card | First findings in minutes