Junglewise Threat Intelligence

CVE-2026-30835: Parse Server information disclosure in $regex query handling

CVE-2026-30835 · Severity: medium · CVSS 4 · Published 2026-03-06

Technologies: Parse Community Parse Server. Vendors: Parse Community.

Executive brief

Parse Server is a backend framework that processes database queries for mobile and web applications. When a malformed `$regex` query parameter is submitted, the server inadvertently exposes detailed database error messages—including error codes, cluster information, and topology details—to any client making requests. This information leakage enables attackers to understand the underlying database architecture and identify further attack vectors.

Technical details

The vulnerability is an information disclosure (CWE-209) in the query execution layer of Parse Server. When a malformed `$regex` query parameter (e.g., `[abc)`) is processed, the database returns a structured error object that is passed unsanitized through the API response to the client. This leaks sensitive database internals such as error messages, error codes, code names, cluster timestamps, and topology details. The vulnerability requires no authentication or user interaction and is exploitable by any client capable of sending query requests to the API. The fix sanitizes database error objects to return only a generic "An internal server error occurred" message to clients while logging the detailed error server-side, respecting the `enableSanitizedErrorResponse` server option.

Affected products

  • Parse Community Parse Server < 8.6.7; >= 9.0.0 and < 9.5.0-alpha.6

Timeline

  • 2026-03-06: disclosed
  • 2026-03-06: advisory: GHSA-9cp7-3q5w-j92g published
  • 2026-03-06: patched: Patches released in versions 8.6.7 and 9.5.0-alpha.6

References