CVE-2026-93761
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an embedded association may become unresponsive.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB Inc. | Mongoid | 7.2.0 <= 7.2.6 | affected |
| MongoDB Inc. | Mongoid | 7.3.0 <= 7.3.5 | affected |
| MongoDB Inc. | Mongoid | 7.4.0 <= 7.4.3 | affected |
| MongoDB Inc. | Mongoid | 7.5.0 <= 7.5.4 | affected |
| MongoDB Inc. | Mongoid | 7.6.0 <= 7.6.1 | affected |
| MongoDB Inc. | Mongoid | 8.0.0 <= 8.0.12 | affected |
| MongoDB Inc. | Mongoid | 8.1.0 <= 8.1.12 | affected |
| MongoDB Inc. | Mongoid | 9.0.0 <= 9.0.11 | affected |
| MongoDB Inc. | Mongoid | 9.1.0 | affected |
Weaknesses
- CWE-1333: CWE-1333: Inefficient Regular Expression Complexity
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.