
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33498 is a Denial-of-Service vulnerability in Parse Server (an open-source Node.js backend) caused by uncontrolled recursion in query condition processing. An unauthenticated attacker can send a crafted HTTP request containing a deeply nested query with logical operators ($and, $or, $nor) to permanently hang the server process, requiring a manual restart. This vulnerability is a bypass of the prior fix for CVE-2026-32944. It affects all Parse Server versions before 8.6.55 and versions 9.0.0 through 9.6.0-alpha.43. It was disclosed on March 20, 2026, with a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, Parse Server Advisory).
The root cause is CWE-674 (Uncontrolled Recursion) in src/RestQuery.js. The prior fix for CVE-2026-32944 placed the query depth guard (validateQuery()) after the transformation pipeline in the execute() method. Because the RestQuery.js transform pipeline recursively traverses the query structure before validateQuery() is reached, a sufficiently deep nesting (e.g., depth 50 using $and, $or, or $nor operators) causes the Node.js process to hang indefinitely before the depth guard can fire. The fix adds a new validateQueryDepth() method that is invoked as the first step in execute(), checking nesting depth against the configured requestComplexity.queryDepth limit before any transformation occurs. The check applies to non-master, non-maintenance authenticated requests and traverses $or, $and, and $nor operators recursively (GitHub Advisory, Patch Commit).
Successful exploitation results in a complete and permanent denial of service for the Parse Server process — the server becomes fully unresponsive and must be manually restarted, causing total unavailability of any application backend relying on Parse Server. There is no confidentiality or integrity impact; the attack is purely an availability attack. Because no authentication is required, any internet-exposed Parse Server instance is at risk, and repeated attacks can prevent recovery without automated restart mechanisms (GitHub Advisory, Parse Server Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable by any network-accessible attacker. The EPSS score is approximately 0.045% (6th percentile), indicating a currently low probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).
$and, $or, or $nor. For example, start with { "username": "test" } and wrap it 50 times: { "$and": [{ "$and": [... ] }] }.GET or POST request to a Parse Server class endpoint (e.g., GET /classes/_User?where=<encoded_nested_query>), including only the required X-Parse-Application-Id header (which is typically public).RestQuery.js recursively traverses the deeply nested structure before the depth guard fires, causing the Node.js event loop to hang indefinitely./classes/*, /1/classes/*) with abnormally large or deeply nested where query parameters encoded in the URL or request body.where parameter immediately before the server becomes unresponsive; absence of response log entries following such requests.Upgrade Parse Server immediately to version 8.6.55 (for the v8 branch) or 9.6.0-alpha.44 / 9.6.0 (for the v9 branch), which add pre-validation depth checking before the transform pipeline (Parse Server Advisory). The official advisory states there are no workarounds for unpatched versions. As a temporary operational measure while patching, consider implementing network-level request filtering (e.g., WAF rules) to block requests with abnormally large where parameters, and configure automated process restart mechanisms (e.g., PM2, systemd) to minimize downtime if exploitation occurs (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."