CVE-2026-93761
Last modified
CVE-2026-93761 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an embedded association may become unresponsive..
Description
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an embedded association may become unresponsive.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MongoDB Inc. | Mongoid | >= 7.2.0, <= 7.2.6; >= 7.3.0, <= 7.3.5; >= 7.4.0, <= 7.4.3; >= 7.5.0, <= 7.5.4; >= 7.6.0, <= 7.6.1; >= 8.0.0, <= 8.0.12; >= 8.1.0, <= 8.1.12; >= 9.0.0, <= 9.0.11; 9.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-93761?
How severe is CVE-2026-93761?
How do I fix CVE-2026-93761?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-93752CSSOM through 0.5.0 contains a denial of service vulnerabili…7.5
- CVE-2026-93753deepmerge through 4.3.1 contains a prototype poisoning vulne…7.5
- CVE-2026-93758An insecure direct object reference in the nested attributes…8.1
- CVE-2026-93759Mongoid does not neutralize a string-typed query criterion s…8.6
- CVE-2026-9376A vulnerability was determined in JPress up to 1.0.3. The af…6.3
- CVE-2026-93760Mongoid does not restrict which query operators may come fro…8.2
- CVE-2026-93762Mongoid contains an unsafe reflection weakness in the query …9.8
- CVE-2026-93763A protection mechanism failure in the object-document mapper…6.5
- CVE-2026-93764Mongoid may omit encryption rules for fields declared on emb…6.5
- CVE-2026-93765Mongoid contains an unsafe reflection weakness in the docume…9.1
- CVE-2026-9377A vulnerability was identified in SourceCodester SUP Online …2.4
- CVE-2026-9378A security flaw has been discovered in Edimax BR-6675nD 1.12…6.3
Are you affected by CVE-2026-93761?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
