Mongoid ReDoS in Query Evaluation Leads to DoS
CVE-2026-93761 Published on September 18, 2026
Denial of service via unbounded regex matching in Mongoid's in-memory query matcher
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an embedded association may become unresponsive.
Vulnerability Analysis
CVE-2026-93761 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is a ReDoS Vulnerability?
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles. Some regular expression engines have a feature called "backtracking". If the token cannot match, the engine "backtracks" to a position that may result in a different token that can match. Backtracking becomes a weakness if all of these conditions are met:
CVE-2026-93761 has been classified to as a ReDoS vulnerability or weakness.
Affected Versions
MongoDB Inc. Mongoid:- Version 7.2.0, <= 7.2.6 is affected.
- Version 7.3.0, <= 7.3.5 is affected.
- Version 7.4.0, <= 7.4.3 is affected.
- Version 7.5.0, <= 7.5.4 is affected.
- Version 7.6.0, <= 7.6.1 is affected.
- Version 8.0.0, <= 8.0.12 is affected.
- Version 8.1.0, <= 8.1.12 is affected.
- Version 9.0.0, <= 9.0.11 is affected.
- Version 9.1.0 is affected.