CVE-2026-30972: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-30972 is a rate limit bypass vulnerability in Parse Server, an open-source Node.js backend platform, that allows unauthenticated remote attackers to circumvent configured rate limiting protections via the batch request endpoint (/batch). It affects all Parse Server versions prior to 8.6.23 and versions 9.0.0 through 9.5.2-alpha.9 (i.e., prior to 9.5.2-alpha.10). The vulnerability was disclosed on March 10, 2026, with patches released on March 8, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.9 (Medium) (Github Advisory, Parse Server Advisory).

Technical details

The root cause is classified as CWE-799 (Improper Control of Interaction Frequency). Parse Server's rate limiting middleware is enforced at the Express.js middleware layer; however, the /batch endpoint processes sub-requests by routing them internally through the Promise router, which bypasses Express middleware entirely — including rate limiting. An unauthenticated attacker can craft a single batch request containing multiple sub-requests targeting a rate-limited endpoint, effectively multiplying the number of requests processed without triggering the rate limit counter. No special privileges or user interaction are required, and the attack is executable remotely over the network (Github Advisory, Parse Server Advisory).

Impact

Successful exploitation allows attackers to bypass rate limiting protections on any rate-limited Parse Server endpoint, enabling abuse attacks such as brute force credential attacks, credential stuffing, or resource exhaustion against the server. There is no direct confidentiality or integrity impact on the vulnerable system itself, but downstream systems may be affected through reduced availability (rated Low for subsequent system availability). Any Parse Server deployment relying on the built-in rate limiting feature is affected, potentially exposing authentication endpoints and other sensitive API routes to high-volume automated attacks (Github Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation at this time (Github Advisory). The vulnerability has an EPSS score of approximately 0.062% (19th percentile), indicating a low near-term exploitation probability. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The attack requires no authentication, no user interaction, and low complexity, making it straightforward to exploit if a target is identified.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Parse Server instances (versions < 8.6.23 or 9.0.0–9.5.2-alpha.9) using tools like Shodan or Censys, or by inspecting application API endpoints for Parse Server signatures.
  2. Identify rate-limited endpoints: Probe the target Parse Server to determine which endpoints (e.g., login, password reset) have rate limiting configured by sending individual requests and observing rate limit responses.
  3. Craft a batch request: Construct a single HTTP POST request to the /batch endpoint containing multiple sub-requests targeting the rate-limited endpoint. For example:
POST /1/batch
Content-Type: application/json

{
  "requests": [
    {"method": "POST", "path": "/1/login", "body": {"username": "victim", "password": "attempt1"}},
    {"method": "POST", "path": "/1/login", "body": {"username": "victim", "password": "attempt2"}},
    ...
  ]
}
  1. Bypass rate limit: Because sub-requests are routed through the Promise router internally, they bypass Express middleware rate limiting. The server processes all sub-requests without enforcing the configured rate limit.
  2. Achieve objective: Repeat batch requests to conduct brute force, credential stuffing, or resource exhaustion attacks against the target endpoint at a rate far exceeding the configured limit (Parse Server Advisory).

Indicators of compromise

  • Network: High volume of HTTP POST requests to the /batch endpoint (e.g., /1/batch) from a single or small set of source IP addresses; batch requests containing unusually large numbers of sub-requests targeting authentication or sensitive endpoints.
  • Logs: Parse Server access logs showing repeated batch requests with many sub-requests to rate-limited paths (e.g., /1/login, /1/requestPasswordReset) within short time windows; absence of rate limit rejection responses (HTTP 429) despite high request volumes to sensitive endpoints.
  • Application Behavior: Unusual spikes in failed authentication attempts or password reset requests that do not correlate with expected rate limit enforcement; accounts showing signs of brute force activity (multiple failed logins in rapid succession) (Parse Server Advisory).

Mitigation and workarounds

Upgrade Parse Server to version 8.6.23 (for the 8.x branch) or 9.5.2-alpha.10 (for the 9.x branch), both released on March 8, 2026. The fix adds a pre-flight check in the batch request handler that counts sub-requests targeting each rate-limited path and rejects the entire batch if any path's count exceeds its configured requestCount. As a workaround for deployments that cannot immediately upgrade, implement rate limiting at the network level using a reverse proxy (e.g., Nginx) or a Web Application Firewall (WAF) to enforce limits before requests reach Parse Server. Note that even after patching, the advisory recommends using a reverse proxy or WAF for comprehensive rate limiting, as the server-level fix does not account for requests already consumed in the current time window by previous individual requests (Parse Server Advisory, Release 8.6.23, Release 9.5.2-alpha.10).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management