Junglewise Threat Intelligence

CVE-2026-30946: Parse Server denial-of-service via unbounded query complexity

CVE-2026-30946 · Severity: medium · CVSS 4 · Published 2026-03-11

Technologies: Parse Community Parse Server. Vendors: Parse Community.

Executive brief

Parse Server is a popular backend-as-a-service platform that powers mobile and web applications. An unauthenticated attacker can crash or severely degrade the service by sending specially crafted queries to the REST or GraphQL APIs that consume excessive CPU, memory, and database connections without restriction. This can cause service outages affecting all users of the Parse Server deployment.

Technical details

The vulnerability exists in Parse Server's REST and GraphQL API implementations, which lack built-in limits on query complexity (CWE-770: Allocation of Resources Without Limits or Throttling). An attacker can craft queries with deeply nested subqueries, includes, or GraphQL field selections to trigger unbounded resource consumption. The vulnerability requires no authentication, no special privileges, and no user interaction—a simple network request is sufficient. Attackers can exhaust CPU, memory, and database connections, leading to denial of service. The fix involves adding configurable requestComplexity limits (subqueryDepth, includeDepth, includeCount, graphQLDepth, graphQLFields). Patched versions are 8.6.15, 8.6.46, 9.5.2-alpha.2, and 9.6.0-alpha.22 or later.

Affected products

  • Parse Community Parse Server < 8.6.15 and >= 9.0.0 < 9.5.2-alpha.2

Timeline

  • 2026-03-11: disclosed: GHSA-cmj3-wx7h-ffvg published
  • 2026-03-11: patched: Parse Server 8.6.15 and 9.5.2-alpha.2 released with fix

References