#VU124988 Improper control of interaction frequency in Parse Server - CVE-2026-30972
Published: April 6, 2026
Parse Server
Parse Community
Description
The vulnerability allows a remote attacker to bypass configured rate limits.
The vulnerability exists due to improper control of interaction frequency in the batch request endpoint when processing batch requests containing multiple sub-requests for rate-limited paths. A remote attacker can send a specially crafted batch request to bypass configured rate limits.
Any deployment that relies on the built-in rate limiting feature is affected.