Description
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an embedded association may become unresponsive.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an inefficient regular expression handling in Mongoid's in‑memory query matcher, designated CWE-1333, allowing a malicious user to submit a pattern that triggers excessive CPU and memory consumption, resulting in denial of service to the application process.

Affected Systems

Affected systems include applications built with MongoDB Inc.'s Mongoid library. No specific product versions are listed in the advisory, so all supported releases of Mongoid that incorporate the in‑memory query matcher should be considered at risk.

Risk and Exploitability

With a CVSS score of 8.7 the vulnerability is high severity. The EPSS of < 1% indicates low current exploitation probability, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote via unauthenticated user‑supplied input to a query that contains a regex. An attacker can craft a pattern that causes the in‑memory matcher to perform extreme backtracking or allocation, causing the application to become unresponsive or crash. Because the flaw resides in the application layer, it can be mitigated by patching or by restricting regex complexity.

Generated by OpenCVE AI on September 19, 2026 at 16:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Mongoid to the latest version that resolves the regular expression inefficiency.
  • Validate or restrict user‑supplied regex patterns before they are used in query conditions, for example by enforcing a maximum length or by prohibiting complex constructs.
  • If updating is not feasible immediately, isolate the application in a protected process or container and monitor for CPU/memory spikes, restarting the service automatically on high usage.

Generated by OpenCVE AI on September 19, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:mongoid:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongoid:9.1.0:*:*:*:*:*:*:*

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongoid
Vendors & Products Mongodb
Mongodb mongoid

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an embedded association may become unresponsive.
Title Denial of service via unbounded regex matching in Mongoid's in-memory query matcher
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-19T14:11:43.253Z

Reserved: 2026-09-18T16:51:40.241Z

Link: CVE-2026-93761

cve-icon Vulnrichment

Updated: 2026-09-19T14:10:13.638Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T18:18:34.917

Modified: 2026-09-24T16:06:04.550

Link: CVE-2026-93761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:05Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity