
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32770 is a denial-of-service vulnerability in Parse Server's LiveQuery feature, where a remote attacker can crash the server by subscribing with an invalid regular expression pattern. The server process terminates when the malformed pattern reaches the regex engine during subscription matching, causing a denial of service for all connected clients. It affects Parse Server versions prior to 8.6.43 (all versions in the 8.x line) and versions 9.0.0 through 9.6.0-alpha.18 in the 9.x line. The vulnerability was published on March 16, 2026, and patched on March 14, 2026. The GitHub Advisory Database assigns a CVSS v3.1 score of 5.9 (Moderate), while the NVD assigns 7.5 (High) (GitHub Advisory, Parse Server Advisory).
The root cause is an uncaught exception (CWE-248) combined with improper input validation (CWE-20) in the LiveQuery subscription handling code within ParseLiveQueryServer.ts. When a client subscribes to a LiveQuery with a $regex query constraint containing an invalid regular expression pattern, the pattern is stored without validation and later passed to the regex engine during subscription matching, causing an unhandled exception that terminates the Node.js server process. The fix introduces a _validateQueryConstraints() method that validates $regex patterns (including those nested in $or/$and/$nor operators) at subscription time, rejecting invalid patterns before storage, and wraps per-subscription matching in a try-catch to prevent any future errors from crashing the server (GitHub Advisory, Fix PR #10197, Fix PR #10199).
Successful exploitation results in a complete availability impact: the Parse Server Node.js process terminates, causing a denial of service for all clients connected to the server, including those with valid, unrelated subscriptions. There is no confidentiality or integrity impact — the vulnerability is purely a DoS vector. Because the server process itself crashes (rather than just a single connection being dropped), all active sessions and LiveQuery subscriptions are disrupted until the server is restarted (GitHub Advisory, Parse Server Advisory).
No public exploit code or in-the-wild exploitation has been reported for CVE-2026-32770. The vulnerability requires no authentication and no user interaction, making it trivially exploitable by any remote attacker who can reach the LiveQuery WebSocket endpoint. The EPSS score is approximately 0.098% (0.042% per GitHub Advisory), placing it in the 13th percentile for exploitation likelihood. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
ws://<target>:<port>/1).$regex pattern, such as { "op": "subscribe", "requestId": 1, "query": { "className": "TestObject", "where": { "field": { "$regex": "[invalid" } } } }.ParseLiveQueryServer.ts or QueryTools.js; sudden absence of log output indicating process termination.Upgrade Parse Server to version 8.6.43 (LTS/stable 8.x line) or 9.6.0-alpha.19 (or later, including the stable 9.6.0 release) to apply the fix (Fix PR #10199, Fix PR #10197). As an immediate workaround, disable LiveQuery if it is not required for your application — this eliminates the attack surface entirely. If LiveQuery must remain enabled and patching is not immediately possible, consider placing the LiveQuery WebSocket endpoint behind a network-level control (e.g., firewall, API gateway) that restricts access to authenticated or trusted clients only (GitHub Advisory, Parse Server Advisory).
The vulnerability was reported by security researcher fancymalware and coordinated by Parse Server maintainer mtrezza, who published the advisory and patches on March 14–16, 2026. The fix was noted as part of a broader Parse Server 9.6.0 release that addressed a large number of security issues simultaneously. No significant independent researcher commentary or media coverage beyond standard CVE aggregator reporting has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."