CVE-2026-32944
Impact
An unauthenticated attacker can crash the Parse Server process by sending a single request with deeply nested query condition operators. This terminates the server and denies service to all connected clients.
Patches
A depth limit for query condition operator nesting has been added via the requestComplexity.queryDepth server option. The option is disabled by default to avoid a breaking change. To mitigate, upgrade and set the option to a value appropriate for your app.
Workarounds
None.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/parse-community/parse-server/security/advisories/GHSA-9xp9-j92r-p88v, https://nvd.nist.gov/vuln/detail/CVE-2026-32944, https://github.com/parse-community/parse-server/pull/10202, https://github.com/parse-community/parse-server/pull/10203, https://github.com/parse-community/parse-server
