<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T20:43:23.065576+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-parse-2026-33498</id>
    <title>BIT-parse-2026-33498 — Parse Server: Query condition depth bypass via pre-validation transform pipeline</title>
    <updated>2026-10-08T20:43:23.115054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: parse</p>
<p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.55 and 9.6.0, an attacker can send an unauthenticated HTTP request with a deeply nested query containing logical operators to permanently hang the Parse Server process. The server becomes completely unresponsive and must be manually restarted. This is a bypass of the fix for CVE-2026-32944. This issue has been patched in versions 8.6.55 and 9.6.0</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-parse-2026-33498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277692</id>
    <title>EUVD-2026-277692</title>
    <updated>2026-10-08T20:43:23.115121+00:00</updated>
    <content>EUVD-2026-277692</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277692"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33498</id>
    <title>fkie_cve-2026-33498</title>
    <updated>2026-10-08T20:43:23.115154+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.55 and 9.6.0-alpha.44, an attacker can send an unauthenticated HTTP request with a deeply nested query containing logical operators to permanently hang the Parse Server process. The server becomes completely unresponsive and must be manually restarted. This is a bypass of the fix for CVE-2026-32944. This issue has been patched in versions 8.6.55 and 9.6.0-alpha.44.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9fjp-q3c4-6w3j</id>
    <title>GHSA-9fjp-q3c4-6w3j — Parse Server has a query condition depth bypass via pre-validation transform pipeline</title>
    <updated>2026-10-08T20:43:23.115185+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: parse-server</p>
<p>### Impact</p>
<p>An attacker can send an unauthenticated HTTP request with a deeply nested query containing logical operators to permanently hang the Parse Server process. The server becomes completely unresponsive and must be manually restarted. This is a bypass of the fix for CVE-2026-32944.</p>
<p>### Patches</p>
<p>The query condition nesting depth is now validated before the query enters the transformation pipeline, preventing deeply nested structures from being recursively processed before the existing depth guard can fire.</p>
<p>### Workarounds</p>
<p>None.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9fjp-q3c4-6w3j"/>
  </entry>
</feed>
