
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34573 is a denial-of-service vulnerability in Parse Server, an open-source Node.js backend framework, caused by inefficient algorithmic complexity (CWE-407) in its GraphQL query complexity validator. An unauthenticated attacker can send a crafted GraphQL query using binary fan-out fragment spreads to trigger exponential O(2^N) traversal, blocking the Node.js event loop for seconds and denying service to all concurrent users. The vulnerability affects Parse Server versions prior to 8.6.68 (all 8.x releases) and versions 9.0.0 through 9.7.0-alpha.11 (all 9.x pre-releases before alpha.12). It was published on March 31, 2026, with patches released on March 29, 2026. The CVSS v3.1 base score is 7.5 (High) and the CVSS v4.0 base score is 8.2 (High) (GitHub Advisory).
The root cause is CWE-407 (Inefficient Algorithmic Complexity) in the calculateQueryComplexity function within src/GraphQL/helpers/queryComplexity.js. The vulnerable code cloned the visitedFragments set per branch (new Set(visitedFragments)) when traversing fragment spreads, causing each fragment reference to be re-traversed independently rather than memoized. A crafted query using binary fan-out — where each fragment spreads the next fragment twice (e.g., fragment F0 on Query { ...F1 ...F1 }) — results in O(2^N) field visits; with 26 levels, this yields approximately 33 million field visits, hanging the event loop. This vulnerability is only exploitable when the requestComplexity.graphQLDepth or requestComplexity.graphQLFields configuration options are enabled (non-default). The fix replaces per-branch set cloning with memoized fragment computation and adds early termination once configured limits are exceeded, reducing traversal complexity to O(N) (GitHub Advisory, Fix PR #10344, Fix PR #10345).
Successful exploitation causes complete availability loss for the affected Parse Server instance by blocking the Node.js event loop for seconds per request, denying service to all concurrent users. Because Node.js is single-threaded, a single unauthenticated HTTP request is sufficient to stall all in-flight requests during the event loop block. There is no confidentiality or integrity impact — the vulnerability is purely a denial-of-service condition. Repeated requests could sustain a near-continuous outage with minimal attacker resources (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The vulnerability requires no authentication and no user interaction, and is exploitable remotely over the network, making it trivially weaponizable against any exposed Parse Server deployment with the relevant configuration options enabled. The EPSS score is approximately 0.045% (very low probability of exploitation in the near term). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
requestComplexity.graphQLDepth or requestComplexity.graphQLFields configuration options are enabled (non-default).query Q { ...F0 }
fragment F0 on Query { ...F1 ...F1 }
fragment F1 on Query { ...F2 ...F2 }
...
fragment F25 on Query { __typename }This results in 2^25 ≈ 33 million field visits during complexity validation.
3. Send the request: Submit the crafted query as an unauthenticated HTTP POST to the Parse Server GraphQL endpoint (e.g., /graphql). No credentials or session tokens are required.
4. Achieve denial of service: The complexity validator traverses fragments exponentially, blocking the Node.js event loop for seconds. All concurrent users are denied service during this period. Repeating the request sustains the outage (GitHub Advisory, Fix PR #10344).
/graphql) containing deeply nested or repetitive fragment spread patterns; requests with unusually large query bodies composed of many fragment definitions.Upgrade Parse Server to version 8.6.68 (for the 8.x LTS branch) or 9.7.0-alpha.12 (for the 9.x branch) or later, which replace the exponential fragment traversal with memoized O(N) computation and add early termination (GitHub Advisory, Fix PR #10345, Fix PR #10344). As an immediate workaround for deployments that cannot patch, disable the vulnerable configuration options by setting requestComplexity.graphQLDepth and requestComplexity.graphQLFields to -1 (the default value, which disables complexity limiting). Additionally, consider implementing network-level rate limiting on the GraphQL endpoint to reduce exposure until patching is complete.
The vulnerability was reported by the researcher bugbunny-research and coordinated by Parse Server maintainer mtrezza, who published the GitHub Security Advisory (GHSA-mfj6-6p54-m98c) and merged fixes for both the 8.x and 9.x branches on March 29, 2026 (GitHub Advisory). The issue was noted in automated threat intelligence feeds and vulnerability databases shortly after disclosure, with no significant broader media coverage or notable community controversy observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."