Junglewise Threat Intelligence

CVE-2026-30925: Parse Server regular expression denial of service in LiveQuery

CVE-2026-30925 · Severity: medium · CVSS 4 · Published 2026-03-10

Technologies: Parse Community Parse Server. Vendors: Parse Community.

Executive brief

Parse Server is a backend-as-a-service platform that provides database and query functionality for applications. LiveQuery is a real-time subscription feature that allows clients to be notified when data changes. An attacker can craft a malicious regex pattern in a LiveQuery subscription that causes excessive processing, blocking the entire server and making it unresponsive to all users. The attack requires only public credentials (application ID and JavaScript key) that are embedded in client applications.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) in Parse Server's LiveQuery subscription matching, classified as CWE-1333 (inefficient regular expression complexity). When a client subscribes to a LiveQuery with a crafted $regex pattern, the regex engine performs catastrophic backtracking on the Node.js event loop, blocking all event processing. The attack is network-reachable and requires no authentication beyond knowledge of public client-side credentials; no user interaction is needed. LiveQuery subscriptions are uniquely vulnerable because regex evaluation occurs in JavaScript on the event loop, whereas normal REST and GraphQL queries delegate regex evaluation to the database engine. Patches were released for Parse Server 8.6.11 and 9.5.0-alpha.14, implementing regex evaluation in an isolated VM with configurable timeout (default 100 ms).

Affected products

  • Parse Community Parse Server all versions before 8.6.11; versions 9.0.0-alpha.1 through 9.5.0-alpha.13

Timeline

  • 2026-03-07: disclosed
  • 2026-03-10: advisory
  • 2026-03-10: patched: Parse Server 8.6.11 and 9.5.0-alpha.14 released

References