CVE Explorer
CVE-2026-34573
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by sending a crafted query with binary fan-out fragment spreads. A single unauthenticated request can block the Node.js event loop for seconds, denying service to all concurrent users. This only affects deployments that have enabled the requestComplexity.graphQLDept
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"parse-server","vendor":"parse-community","versions":[{"status":"affected","version":"< 8.6.68"},{"status":"affected","version":">= 9.0.0, < 9.7.0-alpha.12"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:24f19199f9a22207841877cd51d54c7b64589ea002f93132aed8041234df7550 · sha256:e6afbe793d680c5f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.2,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:24f19199f9a22207841877cd51d54c7b64589ea002f93132aed8041234df7550 · sha256:e6afbe793d680c5f… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-407","description":"CWE-407: Inefficient Algorithmic Complexity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:24f19199f9a22207841877cd51d54c7b64589ea002f93132aed8041234df7550 · sha256:e6afbe793d680c5f… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/parse-community/parse-server/commit/ea15412795f34594cc8a674fe858d445675e0295","tags":["x_refsource_MISC"],"url":"https://github.com/parse-community/parse-server/commit/ea15412795f34594cc8a674fe858d445675e0295"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:24f19199f9a22207841877cd51d54c7b64589ea002f93132aed8041234df7550 · sha256:e6afbe793d680c5f… · /containers/cna/references/3
{"name":"https://github.com/parse-community/parse-server/commit/f759bda075298ec44e2b4fb57659a0c56620483b","tags":["x_refsource_MISC"],"url":"https://github.com/parse-community/parse-server/commit/f759bda075298ec44e2b4fb57659a0c56620483b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:24f19199f9a22207841877cd51d54c7b64589ea002f93132aed8041234df7550 · sha256:e6afbe793d680c5f… · /containers/cna/references/4
{"name":"https://github.com/parse-community/parse-server/pull/10344","tags":["x_refsource_MISC"],"url":"https://github.com/parse-community/parse-server/pull/10344"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:24f19199f9a22207841877cd51d54c7b64589ea002f93132aed8041234df7550 · sha256:e6afbe793d680c5f… · /containers/cna/references/1
{"name":"https://github.com/parse-community/parse-server/pull/10345","tags":["x_refsource_MISC"],"url":"https://github.com/parse-community/parse-server/pull/10345"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:24f19199f9a22207841877cd51d54c7b64589ea002f93132aed8041234df7550 · sha256:e6afbe793d680c5f… · /containers/cna/references/2
{"name":"https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c","tags":["x_refsource_CONFIRM"],"url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:24f19199f9a22207841877cd51d54c7b64589ea002f93132aed8041234df7550 · sha256:e6afbe793d680c5f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.