Inefficient Regular Expression Issue in Mongoid Library by MongoDB
CVE-2026-93761

8.7HIGH

Key Information:

Vendor

MongoDB

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93761?

An inefficiency in the regular expression processing within the Mongoid library can be exploited by unauthenticated users. This vulnerability arises when user-generated content is incorporated into pattern-matching queries related to embedded associations. As a result, applications may experience excessive processing demands, leading to unresponsiveness and impaired functionality, which poses significant operational challenges.

Affected Version(s)

Mongoid 7.2.0 <= 7.2.6

Mongoid 7.3.0 <= 7.3.5

Mongoid 7.4.0 <= 7.4.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.