
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32886 is a prototype chain traversal vulnerability in Parse Server's cloud function dispatch mechanism that allows unauthenticated remote attackers to crash the server process via a stack overflow. It affects Parse Server versions prior to 8.6.47 (all 8.x releases) and versions 9.0.0 through 9.6.0-alpha.23 (all 9.x pre-releases before alpha.24). The vulnerability was disclosed on March 16, 2026, and patched the same day. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.2 (High) (GitHub Advisory, Parse Server Advisory).
The root cause is improper control of object prototype attribute access (CWE-1321) in Parse Server's cloud function name resolution logic within src/triggers.js. When a remote client calls a cloud function endpoint, the server resolves the function handler by looking up the provided function name as a property on the registered handler store object — without restricting lookups to own properties. An attacker can supply a crafted function name (e.g., __proto__ or constructor) that traverses the JavaScript prototype chain, causing the getStore() or get() methods to recurse indefinitely and trigger a stack overflow, crashing the Node.js process. No authentication or user interaction is required; the attack only requires network access to the cloud function endpoint (GitHub Advisory, Parse Server PR #10210).
Successful exploitation results in a complete denial of service: the Parse Server Node.js process crashes and becomes unavailable to all users. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue. Because the attack can be automated and repeated, an attacker can maintain persistent service disruption against any internet-accessible Parse Server deployment running a vulnerable version (GitHub Advisory, Parse Server Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.043% (10th percentile), indicating a low near-term exploitation probability. However, the attack requires no authentication, no user interaction, and is network-accessible with low complexity, making it straightforward to exploit if a PoC were to emerge (Parse Server Advisory).
/1/functions/). Confirm the version is below 8.6.47 or between 9.0.0 and 9.6.0-alpha.23.__proto__ or constructor (e.g., POST /1/functions/__proto__).getStore() or get() method in triggers.js traverses the JavaScript prototype chain recursively when resolving the crafted function name, causing a stack overflow and crashing the Node.js process./1/functions/__proto__, /1/functions/constructor, or other prototype property names on the Parse Server API endpoint; high-frequency requests to cloud function endpoints from a single source IP.__proto__, constructor, toString) returning 400 or 500 errors; Node.js stack overflow error messages in server logs immediately before process termination.RangeError: Maximum call stack size exceeded error; unexpected process restarts if a process manager (e.g., PM2, systemd) is configured (GitHub Advisory, Parse Server PR #10210).Upgrade Parse Server to version 8.6.47 (LTS branch) or 9.6.0-alpha.24 (or later, including the stable 9.6.0 release) immediately. The fix restricts property lookups in getStore() and get() within triggers.js to own properties only (using hasOwnProperty checks), preventing prototype chain traversal. There is no known workaround other than upgrading; as an interim measure, network-level controls (e.g., firewall rules, API gateway filtering) can be used to restrict access to cloud function endpoints from untrusted sources (GitHub Advisory, Parse Server Advisory).
The vulnerability was reported by security researcher fancymalware and coordinated by Parse Server maintainer mtrezza, who published the advisory and patches on March 15–16, 2026 (Parse Server Advisory). The issue received routine coverage from automated vulnerability tracking services and security feeds, with no notable independent researcher commentary or significant social media discussion beyond standard CVE dissemination channels.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."