#VU125007 Uncontrolled Recursion in Parse Server - CVE-2026-33508
Published: April 6, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the LiveQuery subscription handler when processing WebSocket subscription requests with deeply nested logical operators. A remote attacker can send a specially crafted subscription request to cause a denial of service.
Deployments are affected when the LiveQuery WebSocket endpoint is reachable by untrusted clients.