Junglewise Threat Intelligence

CVE-2026-33498: Parse Server query condition depth bypass in transform pipeline

CVE-2026-33498 · Severity: low · CVSS 3.1 · Published 2026-03-20

Technologies: Parse Community Parse Server. Vendors: Parse Community.

Executive brief

Parse Server is a Node.js backend platform used to manage data storage and APIs for applications. An attacker can send an unauthenticated HTTP request with a deeply nested query to permanently hang the server process, making it completely unresponsive until manually restarted. This is a bypass of a previously patched vulnerability and causes a complete denial of service.

Technical details

This vulnerability is a bypass of the fix for CVE-2026-32944 affecting query condition depth validation in Parse Server. The issue is a recursive processing flaw (CWE-674) where deeply nested query structures with logical operators bypass the pre-validation check and cause the transformation pipeline to process them recursively before the depth guard can fire. The attack requires no authentication and is triggered via an unauthenticated HTTP request with a specially crafted query parameter. An attacker can achieve a complete denial of service by causing the Parse Server process to hang. The fix validates query condition nesting depth before the query enters the transformation pipeline, and patches are available in versions 9.6.0-alpha.44 and 8.6.55.

Affected products

  • Parse Community Parse Server versions prior to 8.6.55 and 9.0.0 through 9.6.0-alpha.43

Timeline

  • 2026-03-20: disclosed: Security advisory published
  • 2026-03-20: patched: Patches released in versions 8.6.55 and 9.6.0-alpha.44

References