Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. parse-server
  4. ›
  5. CVE-2026-34573

CVE-2026-34573: parse-server has GraphQL complexity validator exponential fragment traversal DoS

March 31, 2026

The GraphQL query complexity validator can be exploited to cause a denial-of-service by sending a crafted query with binary fan-out fragment spreads. A single unauthenticated request can block the Node.js event loop for seconds, denying service to all concurrent users. This only affects deployments that have enabled the requestComplexity.graphQLDepth or requestComplexity.graphQLFields configuration options.

References

  • github.com/advisories/GHSA-mfj6-6p54-m98c
  • github.com/parse-community/parse-server
  • github.com/parse-community/parse-server/commit/ea15412795f34594cc8a674fe858d445675e0295
  • github.com/parse-community/parse-server/commit/f759bda075298ec44e2b4fb57659a0c56620483b
  • github.com/parse-community/parse-server/pull/10344
  • github.com/parse-community/parse-server/pull/10345
  • github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c
  • nvd.nist.gov/vuln/detail/CVE-2026-34573

Code Behaviors & Features

Detect and mitigate CVE-2026-34573 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 8.6.68, all versions starting from 9.0.0 before 9.7.0-alpha.12

Fixed versions

  • 9.7.0-alpha.12
  • 8.6.68

Solution

Upgrade to versions 8.6.68, 9.7.0-alpha.12 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-407: Inefficient Algorithmic Complexity

Source file

npm/parse-server/CVE-2026-34573.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 07 Apr 2026 00:18:42 +0000.