CVE-2026-32770: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-32770 is a denial-of-service vulnerability in Parse Server's LiveQuery feature, where a remote attacker can crash the server by subscribing with an invalid regular expression pattern. The server process terminates when the malformed pattern reaches the regex engine during subscription matching, causing a denial of service for all connected clients. It affects Parse Server versions prior to 8.6.43 (all versions in the 8.x line) and versions 9.0.0 through 9.6.0-alpha.18 in the 9.x line. The vulnerability was published on March 16, 2026, and patched on March 14, 2026. The GitHub Advisory Database assigns a CVSS v3.1 score of 5.9 (Moderate), while the NVD assigns 7.5 (High) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause is an uncaught exception (CWE-248) combined with improper input validation (CWE-20) in the LiveQuery subscription handling code within ParseLiveQueryServer.ts. When a client subscribes to a LiveQuery with a $regex query constraint containing an invalid regular expression pattern, the pattern is stored without validation and later passed to the regex engine during subscription matching, causing an unhandled exception that terminates the Node.js server process. The fix introduces a _validateQueryConstraints() method that validates $regex patterns (including those nested in $or/$and/$nor operators) at subscription time, rejecting invalid patterns before storage, and wraps per-subscription matching in a try-catch to prevent any future errors from crashing the server (GitHub Advisory, Fix PR #10197, Fix PR #10199).

Impact

Successful exploitation results in a complete availability impact: the Parse Server Node.js process terminates, causing a denial of service for all clients connected to the server, including those with valid, unrelated subscriptions. There is no confidentiality or integrity impact — the vulnerability is purely a DoS vector. Because the server process itself crashes (rather than just a single connection being dropped), all active sessions and LiveQuery subscriptions are disrupted until the server is restarted (GitHub Advisory, Parse Server Advisory).

Exploitability

No public exploit code or in-the-wild exploitation has been reported for CVE-2026-32770. The vulnerability requires no authentication and no user interaction, making it trivially exploitable by any remote attacker who can reach the LiveQuery WebSocket endpoint. The EPSS score is approximately 0.098% (0.042% per GitHub Advisory), placing it in the 13th percentile for exploitation likelihood. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Parse Server instances with LiveQuery enabled by scanning for open WebSocket endpoints (typically on the same port as the Parse Server HTTP API, e.g., port 1337 or 4000).
  2. Establish WebSocket connection: Connect to the Parse Server LiveQuery WebSocket endpoint (e.g., ws://<target>:<port>/1).
  3. Send subscription message: Send a LiveQuery subscribe message containing a query with an invalid $regex pattern, such as { "op": "subscribe", "requestId": 1, "query": { "className": "TestObject", "where": { "field": { "$regex": "[invalid" } } } }.
  4. Trigger server crash: When the server attempts to match the stored subscription against a database event, the invalid regex pattern is passed to the regex engine, throwing an uncaught exception that terminates the Node.js process.
  5. Denial of service achieved: All connected clients lose their connections and the server is unavailable until manually restarted (GitHub Advisory, Fix PR #10197).

Indicators of compromise

  • Network: Unexpected WebSocket connections to the Parse Server LiveQuery endpoint from unknown or untrusted IP addresses; connections that send a subscribe message and immediately disconnect.
  • Logs: Parse Server process crash logs or Node.js unhandled exception stack traces referencing regex evaluation in ParseLiveQueryServer.ts or QueryTools.js; sudden absence of log output indicating process termination.
  • Process: Unexpected termination of the Parse Server Node.js process; process restart events in process managers (e.g., PM2, systemd) shortly after a new WebSocket connection was established.
  • Application: All LiveQuery clients simultaneously disconnecting; server health checks failing immediately after a new subscription was received.

Mitigation and workarounds

Upgrade Parse Server to version 8.6.43 (LTS/stable 8.x line) or 9.6.0-alpha.19 (or later, including the stable 9.6.0 release) to apply the fix (Fix PR #10199, Fix PR #10197). As an immediate workaround, disable LiveQuery if it is not required for your application — this eliminates the attack surface entirely. If LiveQuery must remain enabled and patching is not immediately possible, consider placing the LiveQuery WebSocket endpoint behind a network-level control (e.g., firewall, API gateway) that restricts access to authenticated or trusted clients only (GitHub Advisory, Parse Server Advisory).

Community reactions

The vulnerability was reported by security researcher fancymalware and coordinated by Parse Server maintainer mtrezza, who published the advisory and patches on March 14–16, 2026. The fix was noted as part of a broader Parse Server 9.6.0 release that addressed a large number of security issues simultaneously. No significant independent researcher commentary or media coverage beyond standard CVE aggregator reporting has been identified.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management