{"id":"GHSA-mfj6-6p54-m98c","summary":"parse-server has GraphQL complexity validator exponential fragment traversal DoS","details":"### Impact\n\nThe GraphQL query complexity validator can be exploited to cause a denial-of-service by sending a crafted query with binary fan-out fragment spreads. A single unauthenticated request can block the Node.js event loop for seconds, denying service to all concurrent users. This only affects deployments that have enabled the `requestComplexity.graphQLDepth` or `requestComplexity.graphQLFields` configuration options.\n\n### Patches\n\nThe fix replaces the per-branch fragment traversal with memoized fragment computation, reducing the traversal from exponential O(2^N) to linear O(N) time. Additionally, early termination aborts the traversal as soon as configured limits are exceeded.\n\n### Workarounds\n\nDisable GraphQL complexity limits by setting `requestComplexity.graphQLDepth` and `requestComplexity.graphQLFields` to `-1` (the default).\n\n### Resources\n\n- GitHub security advisory: https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c\n- Fix Parse Server 9: https://github.com/parse-community/parse-server/pull/10344\n- Fix Parse Server 8: https://github.com/parse-community/parse-server/pull/10345","aliases":["BIT-parse-2026-34573","CVE-2026-34573"],"modified":"2026-04-06T15:27:07.040958679Z","published":"2026-03-31T23:49:18Z","database_specific":{"cwe_ids":["CWE-407"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-31T23:49:18Z","nvd_published_at":"2026-03-31T16:16:33Z"},"references":[{"type":"WEB","url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-mfj6-6p54-m98c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34573"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/pull/10344"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/pull/10345"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/commit/ea15412795f34594cc8a674fe858d445675e0295"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/commit/f759bda075298ec44e2b4fb57659a0c56620483b"},{"type":"PACKAGE","url":"https://github.com/parse-community/parse-server"}],"affected":[{"package":{"name":"parse-server","ecosystem":"npm","purl":"pkg:npm/parse-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.0.0"},{"fixed":"9.7.0-alpha.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mfj6-6p54-m98c/GHSA-mfj6-6p54-m98c.json"}},{"package":{"name":"parse-server","ecosystem":"npm","purl":"pkg:npm/parse-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.6.68"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mfj6-6p54-m98c/GHSA-mfj6-6p54-m98c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}