7.3

CVE-2026-32594

Parse Server GraphQL WebSocket endpoint bypasses security middleware

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middleware chain that enforces authentication, introspection control, and query complexity limits. An attacker can connect to the WebSocket endpoint and execute GraphQL operations without providing a valid application or API key, access the GraphQL schema via introspection even when public introspection is disabled, and send arbitrarily complex queries that bypass configured complexity limits. This vulnerability is fixed in 8.6.40 and 9.6.0-alpha.14.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Parseplatform ≫ Parse-server SwPlatform node.js Version < 8.6.40
Parseplatform ≫ Parse-server SwPlatform node.js Version >= 9.0.0 < 9.6.0
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha10 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha11 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha12 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha13 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha2 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha3 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha4 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha5 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha6 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha7 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha8 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha9 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.258
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
security-advisories@github.com 6.9 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://github.com/parse-community/parse-server/security/advisories/GHSA-p2x3-8689-cwpg
Patch
Vendor Advisory
Mitigation
https://github.com/parse-community/parse-server/pull/10189
Patch
Issue Tracking
https://github.com/parse-community/parse-server/pull/10190
Patch
Issue Tracking