CVE-2026-34573 details a high-severity denial-of-service vulnerability in Parse Server, an open-source Node.js backend, affecting versions prior to 8.6.68 and 9.7.0-alpha.12 when GraphQL complexity validation is enabled. Rated 8.2 HIGH, this flaw allows an unauthenticated attacker to block the Node.js event loop for seconds by sending a crafted GraphQL query with binary fan-out fragment spreads, causing a complete service disruption for all concurrent users. There is currently no public exploit code available in common repositories like Metasploit or ExploitDB, and it is not listed on CISA's Known Exploited Vulnerabilities catalog. While community discussion is minimal, organizations using Parse Server should prioritize upgrading to patched versions 8.6.68 or 9.7.0-alpha.12 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.6.68CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
>= 9.0.0, < 9.7.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | ||
9.7.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha1:*:*:*:node.js:*:* | ||
9.7.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha10:*:*:*:node.js:*:* | ||
9.7.0CPE matchmatch criteria | cpe:2.3:a:parseplatform:parse-server:9.7.0:alpha11:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.