
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34363 is a race condition vulnerability in Parse Server's LiveQuery feature, titled "LiveQuery protected field leak via shared mutable state across concurrent subscribers." When multiple clients subscribe to the same class via LiveQuery, event handlers process each subscriber concurrently using shared mutable objects; the sensitive data filter modifies these objects in-place, causing protected fields and authentication data to leak to unauthorized clients, or causing authorized clients to receive incomplete objects. It affects Parse Server (npm) versions < 8.6.65 and >= 9.0.0, < 9.7.0 (including alpha releases up to 9.7.0-alpha.8) for Node.js. The vulnerability was published on March 30, 2026, and has a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 8.2 (High) (Github Advisory).
The root cause is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition). In ParseLiveQueryServer.ts, when a LiveQuery event fires, the server iterates over all subscriber request IDs and processes each concurrently using the same shared mutable parse object. The sensitive data filter (_filterSensitiveData) removes protected fields from this shared object in-place, so if one subscriber's callback executes first and strips a protected field, subsequent subscribers operating on the same object reference will receive the already-modified (incomplete) object. A secondary issue exists with afterEvent Cloud Code triggers: modifications made to req.object within one subscriber's trigger callback leak to other subscribers through the same shared state. Exploitation requires only that multiple clients be subscribed to the same class simultaneously, which is a natural condition in any multi-user application using LiveQuery (Github Advisory, Parse Server PR #10330).
Unauthorized clients subscribing to LiveQuery events may receive sensitive protected fields and authentication data they should not have access to, representing a high confidentiality impact. Conversely, authorized clients (such as master key clients) may receive incomplete objects with protected fields already stripped by another subscriber's filter, causing data integrity issues in the application. Additionally, afterEvent trigger modifications intended for one subscriber can leak to other subscribers, potentially corrupting per-client business logic. There is no availability or integrity impact on the server itself, and no evidence of lateral movement potential beyond data exposure within the Parse Server deployment (Github Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.085% (7th percentile), indicating a low near-term probability of exploitation. Exploitation requires an attacker to be a legitimate (low-privilege) subscriber to the same LiveQuery class as another subscriber with different access rights, and the race condition must be triggered by concurrent event processing — classified as Attack Complexity: High (CVSS v3.1) but Attack Requirements: Present (CVSS v4.0).
protectedFields or afterEvent Cloud Code triggers, and where multiple clients can subscribe to the same class.ws://target:1337) as a low-privilege or regular client and subscribe to a class that has protected fields (e.g., a _User class or custom class with sensitive data).create/update/delete event payload received by the regular client — it may contain protected fields (e.g., secretField, authentication tokens) that should have been filtered out (Github Advisory, Parse Server PR #10330).The Parse Server team has released patches for both supported major versions: Parse Server 8.6.65 (LTS, via PR #10331) and Parse Server 9.7.0 (stable, via PR #10330). The fix deep-clones shared objects at the start of each subscriber's processing callback in ParseLiveQueryServer.ts, ensuring each subscriber works on an independent copy. A secondary bug was also fixed where master key LiveQuery clients could not receive events on classes with protected fields due to an incorrect type passed to the sensitive data filter. There is no known workaround — patching is the only mitigation. If immediate patching is not possible, consider restricting LiveQuery access to only trusted clients or disabling LiveQuery entirely until the patch can be applied (Github Advisory).
The vulnerability was discovered and reported by Parse Server maintainer mtrezza, who also authored the fix. The advisory was published to the GitHub Advisory Database on March 30, 2026, and reviewed the same day. No significant external media coverage or notable third-party researcher commentary has been identified beyond standard vulnerability database aggregation (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."