
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30972 is a rate limit bypass vulnerability in Parse Server, an open-source Node.js backend platform, that allows unauthenticated remote attackers to circumvent configured rate limiting protections via the batch request endpoint (/batch). It affects all Parse Server versions prior to 8.6.23 and versions 9.0.0 through 9.5.2-alpha.9 (i.e., prior to 9.5.2-alpha.10). The vulnerability was disclosed on March 10, 2026, with patches released on March 8, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.9 (Medium) (Github Advisory, Parse Server Advisory).
The root cause is classified as CWE-799 (Improper Control of Interaction Frequency). Parse Server's rate limiting middleware is enforced at the Express.js middleware layer; however, the /batch endpoint processes sub-requests by routing them internally through the Promise router, which bypasses Express middleware entirely — including rate limiting. An unauthenticated attacker can craft a single batch request containing multiple sub-requests targeting a rate-limited endpoint, effectively multiplying the number of requests processed without triggering the rate limit counter. No special privileges or user interaction are required, and the attack is executable remotely over the network (Github Advisory, Parse Server Advisory).
Successful exploitation allows attackers to bypass rate limiting protections on any rate-limited Parse Server endpoint, enabling abuse attacks such as brute force credential attacks, credential stuffing, or resource exhaustion against the server. There is no direct confidentiality or integrity impact on the vulnerable system itself, but downstream systems may be affected through reduced availability (rated Low for subsequent system availability). Any Parse Server deployment relying on the built-in rate limiting feature is affected, potentially exposing authentication endpoints and other sensitive API routes to high-volume automated attacks (Github Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation at this time (Github Advisory). The vulnerability has an EPSS score of approximately 0.062% (19th percentile), indicating a low near-term exploitation probability. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The attack requires no authentication, no user interaction, and low complexity, making it straightforward to exploit if a target is identified.
/batch endpoint containing multiple sub-requests targeting the rate-limited endpoint. For example:POST /1/batch
Content-Type: application/json
{
"requests": [
{"method": "POST", "path": "/1/login", "body": {"username": "victim", "password": "attempt1"}},
{"method": "POST", "path": "/1/login", "body": {"username": "victim", "password": "attempt2"}},
...
]
}/batch endpoint (e.g., /1/batch) from a single or small set of source IP addresses; batch requests containing unusually large numbers of sub-requests targeting authentication or sensitive endpoints./1/login, /1/requestPasswordReset) within short time windows; absence of rate limit rejection responses (HTTP 429) despite high request volumes to sensitive endpoints.Upgrade Parse Server to version 8.6.23 (for the 8.x branch) or 9.5.2-alpha.10 (for the 9.x branch), both released on March 8, 2026. The fix adds a pre-flight check in the batch request handler that counts sub-requests targeting each rate-limited path and rejects the entire batch if any path's count exceeds its configured requestCount. As a workaround for deployments that cannot immediately upgrade, implement rate limiting at the network level using a reverse proxy (e.g., Nginx) or a Web Application Firewall (WAF) to enforce limits before requests reach Parse Server. Note that even after patching, the advisory recommends using a reverse proxy or WAF for comprehensive rate limiting, as the server-level fix does not account for requests already consumed in the current time window by previous individual requests (Parse Server Advisory, Release 8.6.23, Release 9.5.2-alpha.10).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."