Junglewise Threat Intelligence

CVE-2026-32944: Parse Server denial of service via deeply nested query operators

CVE-2026-32944 · Severity: medium · CVSS 4 · Published 2026-03-17

Technologies: Parse Community Parse Server. Vendors: Parse Community.

Executive brief

Parse Server is a backend-as-a-service platform that handles database queries from client applications. An unauthenticated attacker can crash the entire Parse Server process by sending a specially crafted request with deeply nested query condition operators, causing all connected clients to lose access to the service.

Technical details

This vulnerability is a recursive exhaustion flaw (CWE-674) in Parse Server's query condition operator parsing. An unauthenticated attacker can craft a request with deeply nested query operators that consumes stack or memory resources, causing the server process to crash and terminate service for all connected clients. No authentication or user interaction is required; a single network request is sufficient to trigger the denial of service. A fix has been released via a depth limit option (requestComplexity.queryDepth), which is disabled by default to avoid breaking changes. Administrators should upgrade to patched versions (9.6.0-alpha.21 or 8.6.45+) and explicitly enable the depth limit.

Affected products

  • Parse Community Parse Server >=9.0.0, <9.6.0-alpha.21; <8.6.45

Timeline

  • 2026-03-17: disclosed
  • 2026-03-17: patched: Patched versions: 9.6.0-alpha.21 and 8.6.45

References