Executive brief
Parse Server is a backend-as-a-service platform that provides database and query functionality for applications. LiveQuery is a real-time subscription feature that allows clients to be notified when data changes. An attacker can craft a malicious regex pattern in a LiveQuery subscription that causes excessive processing, blocking the entire server and making it unresponsive to all users. The attack requires only public credentials (application ID and JavaScript key) that are embedded in client applications.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) in Parse Server's LiveQuery subscription matching, classified as CWE-1333 (inefficient regular expression complexity). When a client subscribes to a LiveQuery with a crafted $regex pattern, the regex engine performs catastrophic backtracking on the Node.js event loop, blocking all event processing. The attack is network-reachable and requires no authentication beyond knowledge of public client-side credentials; no user interaction is needed. LiveQuery subscriptions are uniquely vulnerable because regex evaluation occurs in JavaScript on the event loop, whereas normal REST and GraphQL queries delegate regex evaluation to the database engine. Patches were released for Parse Server 8.6.11 and 9.5.0-alpha.14, implementing regex evaluation in an isolated VM with configurable timeout (default 100 ms).
Affected products
- Parse Community Parse Server all versions before 8.6.11; versions 9.0.0-alpha.1 through 9.5.0-alpha.13
Timeline
- 2026-03-07: disclosed
- 2026-03-10: advisory
- 2026-03-10: patched: Parse Server 8.6.11 and 9.5.0-alpha.14 released