Inefficient Regular Expression Issue in Mongoid Library by MongoDB
CVE-2026-93761
8.7HIGH
What is CVE-2026-93761?
An inefficiency in the regular expression processing within the Mongoid library can be exploited by unauthenticated users. This vulnerability arises when user-generated content is incorporated into pattern-matching queries related to embedded associations. As a result, applications may experience excessive processing demands, leading to unresponsiveness and impaired functionality, which poses significant operational challenges.
Affected Version(s)
Mongoid 7.2.0 <= 7.2.6
Mongoid 7.3.0 <= 7.3.5
Mongoid 7.4.0 <= 7.4.3