{"id":"CVE-2026-47138","aliases":["BIT-parse-2026-47138","GHSA-38m6-82c8-4xfm"],"url":"https://o3.security/vulnerability/CVE-2026-47138","summary":"Parse Server: Pre-authentication denial of service via client version header regex backtracking","details":"Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-known Parse Application ID can submit a single HTTP request whose client SDK version field contains adversarial input that triggers polynomial backtracking in a request-header parser. The parsing runs before session authentication and before rate limiting on every /parse/* request, so the request consumes seconds to minutes of synchronous CPU on a Node.js worker before any access control evaluates it. A small number of concurrent requests can saturate a worker; a single large request via the body-field variant can pin a worker for minutes. Production deployments running the default configuration are affected. This issue has been patched in versions 8.6.77 and 9.9.1-alpha.1.","published":"2026-06-12T18:22:02.751Z","modified":"2026-08-12T03:51:36.952711537Z","cvss":null,"epss":{"score":0.00584,"percentile":0.44733,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"parse-server","fixedVersion":"9.9.1-alpha.1"},{"ecosystem":"npm","name":"parse-server","fixedVersion":"8.6.77"}],"fix":{"url":"https://github.com/parse-community/parse-server/pull/10463","label":"parse-community/parse-server#10463"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47138.json"},{"type":"ADVISORY","url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-38m6-82c8-4xfm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47138"},{"type":"FIX","url":"https://github.com/parse-community/parse-server/pull/10463"},{"type":"FIX","url":"https://github.com/parse-community/parse-server/pull/10464"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.952711537Z"}}