
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30939 is a Denial of Service (DoS) and Cloud Function Dispatch Bypass vulnerability in Parse Server (npm package by parse-community) caused by improper prototype chain resolution. An unauthenticated attacker can crash the Parse Server process or bypass Cloud Function dispatch validation by supplying JavaScript prototype property names as Cloud Function names. Affected versions include all Parse Server releases prior to 8.6.13 and versions 9.0.0 through 9.5.1-alpha.1. The vulnerability was disclosed on March 7, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.8 (High) (GitHub Advisory, Parse Server Advisory).
The root cause is classified as CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes — Prototype Pollution). Parse Server's internal handler registries for Cloud Functions, Jobs, Triggers, and Validators resolve function names against JavaScript objects without sanitizing prototype chain properties. When an attacker sends a request to the Cloud Function endpoint using a prototype property name (e.g., __proto__, constructor, toString) as the function name, the server enters infinite recursion, exhausting the call stack and terminating the Node.js process. Other prototype property names bypass dispatch validation entirely, returning HTTP 200 responses for non-existent Cloud Functions; dot-notation traversal (e.g., constructor.prototype) is also affected (Parse Server Advisory, GitHub Advisory).
Successful exploitation has two distinct consequences: a complete availability impact via process crash (DoS), and an integrity/logic bypass where attackers receive HTTP 200 responses for non-existent Cloud Functions, potentially enabling system probing or triggering unintended server behavior. There is no confidentiality impact reported. Any Parse Server deployment that exposes the Cloud Function endpoint — regardless of configuration — is vulnerable, and exploitation requires no authentication or user interaction (Parse Server Advisory, GitHub Advisory).
No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.062–0.181% (low probability of exploitation within 30 days). However, the attack requires no authentication, no special privileges, and no user interaction, making it trivially exploitable against any exposed Parse Server instance once an attacker identifies the target.
/parse/functions/)./parse/functions/testFunction and observing the response.POST /parse/functions/__proto__ or POST /parse/functions/constructor. No authentication headers are required.toString, hasOwnProperty) or dot-notation traversal (e.g., constructor.prototype) to receive HTTP 200 responses for non-existent Cloud Functions, enabling enumeration or probing of server behavior without crashing the process (Parse Server Advisory, GitHub Advisory)./parse/functions/__proto__, /parse/functions/constructor, /parse/functions/toString, /parse/functions/hasOwnProperty, or similar prototype property names; requests using dot-notation traversal such as /parse/functions/constructor.prototype.RangeError: Maximum call stack size exceeded errors originating from Cloud Function dispatch code.Upgrade Parse Server to version 8.6.13 (for the 8.x branch) or 9.5.1-alpha.2 (for the 9.x branch), which fix the issue by preventing prototype chain properties from being resolved in internal handler registries (Parse Server 8.6.13 Release, Parse Server 9.5.1-alpha.2 Release). As a temporary workaround, place a reverse proxy or Web Application Firewall (WAF) in front of Parse Server and configure it to block requests to Cloud Function endpoints where the function name matches known JavaScript Object.prototype property names (e.g., __proto__, constructor, toString, hasOwnProperty). Additionally, restrict network access to the Cloud Function endpoint to only authorized clients where operationally feasible (Parse Server Advisory).
The vulnerability was reported by security researcher theinfosecguy and coordinated by Parse Server maintainer mtrezza, who published the advisory and patches simultaneously on March 7, 2026 (Parse Server Advisory). The disclosure received limited but notable attention in automated CVE tracking communities, including mentions on Bluesky CVE feeds and CVEnew Twitter mirrors shortly after publication. No significant broader media coverage or notable researcher commentary beyond the official advisory has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."