<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T01:23:15.956416+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-parse-2026-33508</id>
    <title>BIT-parse-2026-33508 — Parse Server: LiveQuery subscription query depth bypass</title>
    <updated>2026-10-09T01:23:16.008204+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: parse</p>
<p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.56 and 9.6.0, Parse Server's LiveQuery component does not enforce the requestComplexity.queryDepth configuration setting when processing WebSocket subscription requests. An attacker can send a subscription with deeply nested logical operators, causing excessive recursion and CPU consumption that degrades or disrupts service availability. This issue has been patched in versions 8.6.56 and 9.6.0</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-parse-2026-33508"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277421</id>
    <title>EUVD-2026-277421</title>
    <updated>2026-10-09T01:23:16.008268+00:00</updated>
    <content>EUVD-2026-277421</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277421"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33508</id>
    <title>fkie_cve-2026-33508</title>
    <updated>2026-10-09T01:23:16.008285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.56 and 9.6.0-alpha.45, Parse Server's LiveQuery component does not enforce the requestComplexity.queryDepth configuration setting when processing WebSocket subscription requests. An attacker can send a subscription with deeply nested logical operators, causing excessive recursion and CPU consumption that degrades or disrupts service availability. This issue has been patched in versions 8.6.56 and 9.6.0-alpha.45.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33508"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6qh5-m6g3-xhq6</id>
    <title>GHSA-6qh5-m6g3-xhq6 — Parse Server LiveQuery subscription query depth bypass</title>
    <updated>2026-10-09T01:23:16.008312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: parse-server</p>
<p>### Impact</p>
<p>Parse Server's LiveQuery component does not enforce the `requestComplexity.queryDepth` configuration setting when processing WebSocket subscription requests. An attacker can send a subscription with deeply nested logical operators, causing excessive recursion and CPU consumption that degrades or disrupts service availability.</p>
<p>Deployments are affected when the LiveQuery WebSocket endpoint is reachable by untrusted clients.</p>
<p>### Patches</p>
<p>The fix adds query condition depth validation to the LiveQuery subscription handler, enforcing the same `requestComplexity.queryDepth` limit that already protects REST API queries.</p>
<p>### Workarounds</p>
<p>There is no known workaround other than upgrading.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6qh5-m6g3-xhq6"/>
  </entry>
</feed>
