CVE-2026-33508
Parse Server: LiveQuery subscription query depth bypass
7.5
HIGH
CVSS 3.1
EPSS 0.34%
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.56 and 9.6.0, Parse Server's LiveQuery component does not enforce the requestComplexity.queryDepth configuration setting when processing WebSocket subscription requests. An attacker can send a subscription with deeply nested logical operators, causing excessive recursion and CPU consumption that degrades or disrupts service availability. This issue has been patched in versions 8.6.56 and 9.6.0
How to fix CVE-2026-33508
To remediate CVE-2026-33508, upgrade the affected package to a fixed version below.
- —upgrade to 8.6.56 or later
- —upgrade to 9.6.0-alpha.45 or later
Is CVE-2026-33508 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 8.6.56, >= 9.0.0, < 9.6.0
- >= 9.0.0, < 9.6.0-alpha.45
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |