CVE-2026-32770: Parse Server: LiveQuery subscription with invalid regular expression crashes server
Impact
A remote attacker can crash the Parse Server by subscribing to a LiveQuery with an invalid regular expression pattern. The server process terminates when the invalid pattern reaches the regex engine during subscription matching, causing denial of service for all connected clients.
Patches
The fix validates regular expression patterns at subscription time, rejecting invalid patterns before they are stored. Additionally, a defense-in-depth try-catch prevents any subscription matching error from crashing the server process.
Workarounds
Disable LiveQuery if it is not needed.
Other sources
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.19 and 8.6.43, a remote attacker can crash the Parse Server by subscribing to a LiveQuery with an invalid regular expression pattern. The server process terminates when the invalid pattern reaches the regex engine during subscription matching, causing denial of service for all connected clients. The fix in 9.6.0-alpha.19 and 8.6.43 validates regular expression patterns at subscription time, rejecting invalid patterns before they are stored. Additionally, a defense-in-depth try-catch prevents any subscription matching error from crashing the server process. As a workaround, disable LiveQuery if it is not needed.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32770?
CVE-2026-32770 has a high severity due to its potential to cause denial of service by crashing the Parse Server.
How do I fix CVE-2026-32770?
To fix CVE-2026-32770, update your Parse Server to version 8.6.43 or version 9.6.0-alpha.19.
What impact does CVE-2026-32770 have on my application?
CVE-2026-32770 can cause disruptions by terminating the server process, impacting all connected clients.
Who is affected by CVE-2026-32770?
Users of Parse Server versions prior to 8.6.43 and between 9.0.0 and 9.6.0-alpha.19 are affected by CVE-2026-32770.
How can a remote attacker exploit CVE-2026-32770?
A remote attacker can exploit CVE-2026-32770 by subscribing to a LiveQuery with an invalid regular expression pattern.