CVE-2026-33498: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-33498 is a Denial-of-Service vulnerability in Parse Server (an open-source Node.js backend) caused by uncontrolled recursion in query condition processing. An unauthenticated attacker can send a crafted HTTP request containing a deeply nested query with logical operators ($and, $or, $nor) to permanently hang the server process, requiring a manual restart. This vulnerability is a bypass of the prior fix for CVE-2026-32944. It affects all Parse Server versions before 8.6.55 and versions 9.0.0 through 9.6.0-alpha.43. It was disclosed on March 20, 2026, with a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, Parse Server Advisory).

Technical details

The root cause is CWE-674 (Uncontrolled Recursion) in src/RestQuery.js. The prior fix for CVE-2026-32944 placed the query depth guard (validateQuery()) after the transformation pipeline in the execute() method. Because the RestQuery.js transform pipeline recursively traverses the query structure before validateQuery() is reached, a sufficiently deep nesting (e.g., depth 50 using $and, $or, or $nor operators) causes the Node.js process to hang indefinitely before the depth guard can fire. The fix adds a new validateQueryDepth() method that is invoked as the first step in execute(), checking nesting depth against the configured requestComplexity.queryDepth limit before any transformation occurs. The check applies to non-master, non-maintenance authenticated requests and traverses $or, $and, and $nor operators recursively (GitHub Advisory, Patch Commit).

Impact

Successful exploitation results in a complete and permanent denial of service for the Parse Server process — the server becomes fully unresponsive and must be manually restarted, causing total unavailability of any application backend relying on Parse Server. There is no confidentiality or integrity impact; the attack is purely an availability attack. Because no authentication is required, any internet-exposed Parse Server instance is at risk, and repeated attacks can prevent recovery without automated restart mechanisms (GitHub Advisory, Parse Server Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable by any network-accessible attacker. The EPSS score is approximately 0.045% (6th percentile), indicating a currently low probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Parse Server instances using tools like Shodan or Censys, targeting Node.js backends running Parse Server versions below 8.6.55 or between 9.0.0 and 9.6.0-alpha.43.
  2. Craft malicious payload: Construct a deeply nested JSON query (depth ≥ 50) using logical operators such as $and, $or, or $nor. For example, start with { "username": "test" } and wrap it 50 times: { "$and": [{ "$and": [... ] }] }.
  3. Send unauthenticated HTTP request: Submit the crafted query as a GET or POST request to a Parse Server class endpoint (e.g., GET /classes/_User?where=<encoded_nested_query>), including only the required X-Parse-Application-Id header (which is typically public).
  4. Trigger uncontrolled recursion: The transform pipeline in RestQuery.js recursively traverses the deeply nested structure before the depth guard fires, causing the Node.js event loop to hang indefinitely.
  5. Achieve denial of service: The Parse Server process becomes completely unresponsive. All subsequent requests time out until an operator manually restarts the server process (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Network: Unusual HTTP GET or POST requests to Parse Server class endpoints (e.g., /classes/*, /1/classes/*) with abnormally large or deeply nested where query parameters encoded in the URL or request body.
  • Logs: Parse Server access logs showing requests with deeply nested JSON structures in the where parameter immediately before the server becomes unresponsive; absence of response log entries following such requests.
  • Process: Node.js process for Parse Server consuming 100% CPU or becoming completely unresponsive without returning errors; process hanging without generating stack traces or crash dumps.
  • Availability: Sudden and complete unavailability of the Parse Server API with no corresponding infrastructure-level outage; repeated occurrences after manual restarts suggesting active exploitation (GitHub Advisory).

Mitigation and workarounds

Upgrade Parse Server immediately to version 8.6.55 (for the v8 branch) or 9.6.0-alpha.44 / 9.6.0 (for the v9 branch), which add pre-validation depth checking before the transform pipeline (Parse Server Advisory). The official advisory states there are no workarounds for unpatched versions. As a temporary operational measure while patching, consider implementing network-level request filtering (e.g., WAF rules) to block requests with abnormally large where parameters, and configure automated process restart mechanisms (e.g., PM2, systemd) to minimize downtime if exploitation occurs (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management