| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p2x3-8689-cwpg | Parse Server's GraphQL WebSocket endpoint bypasses security middleware |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 16 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parse Community
Parse Community parse Server |
|
| Vendors & Products |
Parse Community
Parse Community parse Server |
Fri, 13 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middleware chain that enforces authentication, introspection control, and query complexity limits. An attacker can connect to the WebSocket endpoint and execute GraphQL operations without providing a valid application or API key, access the GraphQL schema via introspection even when public introspection is disabled, and send arbitrarily complex queries that bypass configured complexity limits. This vulnerability is fixed in 8.6.40 and 9.6.0-alpha.14. | |
| Title | Parse Server GraphQL WebSocket endpoint bypasses security middleware | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-16T13:57:44.809Z
Reserved: 2026-03-12T14:54:24.268Z
Link: CVE-2026-32594
Updated: 2026-03-16T13:57:37.229Z
Status : Awaiting Analysis
Published: 2026-03-16T14:19:38.667
Modified: 2026-03-16T14:53:07.390
Link: CVE-2026-32594
No data.
OpenCVE Enrichment
Updated: 2026-03-16T09:24:01Z
Github GHSA