Impact
The vulnerability is an inefficient regular expression handling in Mongoid's in‑memory query matcher, designated CWE-1333, allowing a malicious user to submit a pattern that triggers excessive CPU and memory consumption, resulting in denial of service to the application process.
Affected Systems
Affected systems include applications built with MongoDB Inc.'s Mongoid library. No specific product versions are listed in the advisory, so all supported releases of Mongoid that incorporate the in‑memory query matcher should be considered at risk.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability is high severity. The EPSS of < 1% indicates low current exploitation probability, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote via unauthenticated user‑supplied input to a query that contains a regex. An attacker can craft a pattern that causes the in‑memory matcher to perform extreme backtracking or allocation, causing the application to become unresponsive or crash. Because the flaw resides in the application layer, it can be mitigated by patching or by restricting regex complexity.
OpenCVE Enrichment