7.5

CVE-2026-32770

Parse Server: LiveQuery subscription with invalid regular expression crashes server

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.19 and 8.6.43, a remote attacker can crash the Parse Server by subscribing to a LiveQuery with an invalid regular expression pattern. The server process terminates when the invalid pattern reaches the regex engine during subscription matching, causing denial of service for all connected clients. The fix in 9.6.0-alpha.19 and 8.6.43 validates regular expression patterns at subscription time, rejecting invalid patterns before they are stored. Additionally, a defense-in-depth try-catch prevents any subscription matching error from crashing the server process. As a workaround, disable LiveQuery if it is not needed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Parseplatform ≫ Parse-server SwPlatform node.js Version < 8.6.43
Parseplatform ≫ Parse-server SwPlatform node.js Version >= 9.0.0 < 9.6.0
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha10 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha11 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha12 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha13 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha14 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha15 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha16 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha17 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha18 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha2 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha3 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha4 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha5 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha6 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha7 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha8 SwPlatform node.js
Parseplatform ≫ Parse-server Version 9.6.0 Update alpha9 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.416
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security-advisories@github.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-248 Uncaught Exception

An exception is thrown from a function, but it is not caught.

https://github.com/parse-community/parse-server/security/advisories/GHSA-827p-g5x5-h86c
Vendor Advisory
https://github.com/parse-community/parse-server/pull/10197
Issue Tracking
https://github.com/parse-community/parse-server/pull/10199
Issue Tracking