CVE-2026-34573: Parse Server: GraphQL complexity validator exponential fragment traversal DoS
Impact
The GraphQL query complexity validator can be exploited to cause a denial-of-service by sending a crafted query with binary fan-out fragment spreads. A single unauthenticated request can block the Node.js event loop for seconds, denying service to all concurrent users. This only affects deployments that have enabled the requestComplexity.graphQLDepth or requestComplexity.graphQLFields configuration options.
Patches
The fix replaces the per-branch fragment traversal with memoized fragment computation, reducing the traversal from exponential O(2^N) to linear O(N) time. Additionally, early termination aborts the traversal as soon as configured limits are exceeded.
Workarounds
Disable GraphQL complexity limits by setting requestComplexity.graphQLDepth and requestComplexity.graphQLFields to -1 (the default).
Resources
- GitHub security advisory: https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c - Fix Parse Server 9: https://github.com/parse-community/parse-server/pull/10344 - Fix Parse Server 8: https://github.com/parse-community/parse-server/pull/10345
Other sources
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by sending a crafted query with binary fan-out fragment spreads. A single unauthenticated request can block the Node.js event loop for seconds, denying service to all concurrent users. This only affects deployments that have enabled the requestComplexity.graphQLDepth or requestComplexity.graphQLFields configuration options. This issue has been patched in versions 8.6.68 and 9.7.0-alpha.12.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/parse-serverto a version that resolves this vulnerability.Fixed in 8.6.68 - Upgrade
Upgrade
npm/parse-serverto a version that resolves this vulnerability.Fixed in 9.7.0-alpha.12 - Upgrade
Upgrade
parse-serverto a version that resolves this vulnerability.Fixed in 8.6.68 - Upgrade
Upgrade
parse-serverto a version that resolves this vulnerability.Fixed in 9.7.0-alpha.12 - Configuration
Disable GraphQL complexity limits by setting requestComplexity.graphQLDepth to -1 (the default). This workaround is relevant when requestComplexity.graphQLDepth/requestComplexity.graphQLFields are enabled.
Parse Server (GraphQL complexity validator) requestComplexity.graphQLDepth = -1 - Configuration
Disable GraphQL complexity limits by setting requestComplexity.graphQLFields to -1 (the default). This workaround is relevant when requestComplexity.graphQLDepth/requestComplexity.graphQLFields are enabled.
Parse Server (GraphQL complexity validator) requestComplexity.graphQLFields = -1