๐Ÿ” CVE Alert

CVE-2026-34573

UNKNOWN 0.0

Parse Server: GraphQL complexity validator exponential fragment traversal DoS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by sending a crafted query with binary fan-out fragment spreads. A single unauthenticated request can block the Node.js event loop for seconds, denying service to all concurrent users. This only affects deployments that have enabled the requestComplexity.graphQLDepth or requestComplexity.graphQLFields configuration options. This issue has been patched in versions 8.6.68 and 9.7.0-alpha.12.

CWE CWE-407
Vendor parse-community
Product parse-server
Published Mar 31, 2026
Last Updated Mar 31, 2026
Stay Ahead of the Next One

Get instant alerts for parse-community parse-server

Be the first to know when new unknown vulnerabilities affecting parse-community parse-server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

parse-community / parse-server
< 8.6.68 >= 9.0.0, < 9.7.0-alpha.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c github.com: https://github.com/parse-community/parse-server/pull/10344 github.com: https://github.com/parse-community/parse-server/pull/10345 github.com: https://github.com/parse-community/parse-server/commit/ea15412795f34594cc8a674fe858d445675e0295 github.com: https://github.com/parse-community/parse-server/commit/f759bda075298ec44e2b4fb57659a0c56620483b