An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplie
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB Inc. | Mongoid | 7.2.0≤ 7.2.6 |
affected |
7.3.0≤ 7.3.5 |
affected | ||
7.4.0≤ 7.4.3 |
affected | ||
7.5.0≤ 7.5.4 |
affected | ||
7.6.0≤ 7.6.1 |
affected | ||
8.0.0≤ 8.0.12 |
affected | ||
8.1.0≤ 8.1.12 |
affected | ||
9.0.0≤ 9.0.11 |
affected | ||
| … +1 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB Inc. | Mongoid | 7.2.0 ~ 7.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93762 | 9.8 CRITICAL | Data deletion and attribute disclosure via field-name method injection in in-memory querie |
| CVE-2026-93765 | 9.1 CRITICAL | Document deletion and process crash via unvalidated method-name dispatch in atomic pop ope |
| CVE-2026-93759 | 8.6 HIGH | Server-side JavaScript injection via string query criteria bypassing the strict operator a |
| CVE-2026-93760 | 8.2 HIGH | NoSQL injection of JavaScript-executing query operators via unsafe-by-default operator gua |
| CVE-2026-93758 | 8.1 HIGH | Cross-principal document update, theft, and deletion via unvalidated id in nested attribut |
| CVE-2026-93763 | 6.5 MEDIUM | Silent plaintext persistence via unresolved callable database name in encryption schema ma |
| CVE-2026-93764 | 6.5 MEDIUM | Plaintext storage of encrypted fields via skipped embedded models in encryption schema gen |
No comments yet