CVE-2026-30939Disclosure(parseplatform / parse-server)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch parseplatform parse-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13 and 9.5.1-alpha.2, an unauthenticated attacker can crash the Parse Server process by calling a Cloud Function endpoint with a prototype property name as the function name. The server recurses infinitely, causing a call stack size error that terminates the process. Other prototype property names bypass Cloud Function dispatch validation and return HTTP 200 responses, even though no such Cloud Functions are defined. The same applies to dot-notation traversal. All Parse Server deployments that expose the Cloud Function endpoint are affected. This vulnerability is fixed in 8.6.13 and 9.5.1-alpha.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • parse-server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
parse-server

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-18: 3Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 103-18
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Parse Server, DoS/Bypass, #CVE-2026-30939 (High) https://dailycve.com/parse-server-dos-bypass-cve-2026-30939-high/

    Post summary

    A high‑severity DoS/Bypass vulnerability (CVE‑2026‑30939) in Parse Server has been disclosed, including its type and severity, but no PoC, exploit, patch or active exploitation details are provided.

    0000028
    169 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30939 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13 and 9.5.1-alpha.2, an unauthenticated attacker… https://www.cve.org/CVERecord?id=CVE-2026-30939 ----- Traducción: CVE-2026-30939 Par… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑30939 for Parse Server, noting it allows unauthenticated attackers prior to certain releases, and links to the official CVE record.

    0000032
    60 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-30939 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13 and 9.5.1-alpha.2, an unauthenticated attacker… https://www.cve.org/CVERecord?id=CVE-2026-30939

    Post summary

    The text highlights a CVE with vulnerable versions and indicates patch versions but provides no exploit or active‑use details.

    00000181
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appparseplatformparse-server-node.js-
Appparseplatformparse-server9.5.1node.js-

Explore more