Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alpha.2 and 8.6.15, an unauthenticated attacker can exhaust Parse Server resources (CPU, memory, database connections) through crafted queries that exploit the lack of complexity limits in the REST and GraphQL APIs. All Parse Server deployments using the REST or GraphQL API are affected. This vulnerability is fixed in 9.5.2-alpha.2 and 8.6.15.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cmj3-wx7h-ffvg | Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parse Community
Parse Community parse Server |
|
| Vendors & Products |
Parse Community
Parse Community parse Server |
Tue, 10 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alpha.2 and 8.6.15, an unauthenticated attacker can exhaust Parse Server resources (CPU, memory, database connections) through crafted queries that exploit the lack of complexity limits in the REST and GraphQL APIs. All Parse Server deployments using the REST or GraphQL API are affected. This vulnerability is fixed in 9.5.2-alpha.2 and 8.6.15. | |
| Title | Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-11T15:29:32.830Z
Reserved: 2026-03-07T17:34:39.979Z
Link: CVE-2026-30946
No data.
Status : Awaiting Analysis
Published: 2026-03-10T21:16:47.333
Modified: 2026-03-11T13:52:47.683
Link: CVE-2026-30946
No data.
OpenCVE Enrichment
Updated: 2026-03-11T11:42:58Z
Weaknesses
Github GHSA