CVE-2026-34363: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-34363 is a race condition vulnerability in Parse Server's LiveQuery feature, titled "LiveQuery protected field leak via shared mutable state across concurrent subscribers." When multiple clients subscribe to the same class via LiveQuery, event handlers process each subscriber concurrently using shared mutable objects; the sensitive data filter modifies these objects in-place, causing protected fields and authentication data to leak to unauthorized clients, or causing authorized clients to receive incomplete objects. It affects Parse Server (npm) versions < 8.6.65 and >= 9.0.0, < 9.7.0 (including alpha releases up to 9.7.0-alpha.8) for Node.js. The vulnerability was published on March 30, 2026, and has a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 8.2 (High) (Github Advisory).

Technical details

The root cause is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition). In ParseLiveQueryServer.ts, when a LiveQuery event fires, the server iterates over all subscriber request IDs and processes each concurrently using the same shared mutable parse object. The sensitive data filter (_filterSensitiveData) removes protected fields from this shared object in-place, so if one subscriber's callback executes first and strips a protected field, subsequent subscribers operating on the same object reference will receive the already-modified (incomplete) object. A secondary issue exists with afterEvent Cloud Code triggers: modifications made to req.object within one subscriber's trigger callback leak to other subscribers through the same shared state. Exploitation requires only that multiple clients be subscribed to the same class simultaneously, which is a natural condition in any multi-user application using LiveQuery (Github Advisory, Parse Server PR #10330).

Impact

Unauthorized clients subscribing to LiveQuery events may receive sensitive protected fields and authentication data they should not have access to, representing a high confidentiality impact. Conversely, authorized clients (such as master key clients) may receive incomplete objects with protected fields already stripped by another subscriber's filter, causing data integrity issues in the application. Additionally, afterEvent trigger modifications intended for one subscriber can leak to other subscribers, potentially corrupting per-client business logic. There is no availability or integrity impact on the server itself, and no evidence of lateral movement potential beyond data exposure within the Parse Server deployment (Github Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.085% (7th percentile), indicating a low near-term probability of exploitation. Exploitation requires an attacker to be a legitimate (low-privilege) subscriber to the same LiveQuery class as another subscriber with different access rights, and the race condition must be triggered by concurrent event processing — classified as Attack Complexity: High (CVSS v3.1) but Attack Requirements: Present (CVSS v4.0).

Exploitation steps

  1. Identify target: Locate a Parse Server deployment with LiveQuery enabled that has classes configured with protectedFields or afterEvent Cloud Code triggers, and where multiple clients can subscribe to the same class.
  2. Register as a subscriber: Connect to the Parse Server LiveQuery WebSocket endpoint (e.g., ws://target:1337) as a low-privilege or regular client and subscribe to a class that has protected fields (e.g., a _User class or custom class with sensitive data).
  3. Trigger concurrent event processing: Ensure at least one other client (e.g., a master key client or another regular client) is simultaneously subscribed to the same class. Cause a LiveQuery event (create, update, or delete) to fire on that class — for example, by saving or modifying an object in the class.
  4. Exploit the race condition: Due to the shared mutable object, if the server processes the master key subscriber's callback first (which does not strip protected fields) and then processes the regular client's callback on the same object, the regular client may receive the unfiltered object including protected fields. Conversely, if the regular client's filter runs first, the master key client may receive an already-stripped object.
  5. Receive leaked data: Observe the LiveQuery create/update/delete event payload received by the regular client — it may contain protected fields (e.g., secretField, authentication tokens) that should have been filtered out (Github Advisory, Parse Server PR #10330).

Mitigation and workarounds

The Parse Server team has released patches for both supported major versions: Parse Server 8.6.65 (LTS, via PR #10331) and Parse Server 9.7.0 (stable, via PR #10330). The fix deep-clones shared objects at the start of each subscriber's processing callback in ParseLiveQueryServer.ts, ensuring each subscriber works on an independent copy. A secondary bug was also fixed where master key LiveQuery clients could not receive events on classes with protected fields due to an incorrect type passed to the sensitive data filter. There is no known workaround — patching is the only mitigation. If immediate patching is not possible, consider restricting LiveQuery access to only trusted clients or disabling LiveQuery entirely until the patch can be applied (Github Advisory).

Community reactions

The vulnerability was discovered and reported by Parse Server maintainer mtrezza, who also authored the fix. The advisory was published to the GitHub Advisory Database on March 30, 2026, and reviewed the same day. No significant external media coverage or notable third-party researcher commentary has been identified beyond standard vulnerability database aggregation (Github Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management