PT-2026-24151 · Unknown · Parse Server

Tinkanet

·

Published

2026-03-09

·

Updated

2026-03-18

·

CVE-2026-30925

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 9.5.0-alpha.14 Parse Server versions prior to 8.6.11
Description A crafted $regex pattern within a LiveQuery subscription can cause catastrophic backtracking, blocking the Node.js event loop and rendering the entire Parse Server unresponsive. An attacker requires only the application ID and JavaScript key, typically public in client-side applications, to exploit this issue. This impacts Parse Server deployments with LiveQuery enabled, specifically affecting LiveQuery subscription matching which evaluates regex in JavaScript on the Node.js event loop. Normal REST and GraphQL queries are not affected as their regex evaluation occurs within the database engine.
Recommendations Update to Parse Server version 9.5.0-alpha.14 or later. Update to Parse Server version 8.6.11 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

BIT-PARSE-2026-30925
CVE-2026-30925
GHSA-MF3J-86QX-CQ5J

Affected Products

Parse Server