CVE-2026-93759
- EPSS 0.24%
- Veröffentlicht 18.09.2026 17:27:51
- Zuletzt bearbeitet 24.09.2026 16:19:37
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a ...
CVE-2026-93760
- EPSS 0.28%
- Veröffentlicht 18.09.2026 17:24:03
- Zuletzt bearbeitet 24.09.2026 16:07:38
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party wi...
CVE-2026-93761
- EPSS 0.27%
- Veröffentlicht 18.09.2026 17:20:34
- Zuletzt bearbeitet 24.09.2026 16:06:04
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place us...
CVE-2026-93762
- EPSS 0.34%
- Veröffentlicht 18.09.2026 17:15:17
- Zuletzt bearbeitet 24.09.2026 16:05:13
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disc...
CVE-2026-93763
- EPSS 0.1%
- Veröffentlicht 18.09.2026 17:10:24
- Zuletzt bearbeitet 24.09.2026 16:00:39
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning....
CVE-2026-93764
- EPSS 0.1%
- Veröffentlicht 18.09.2026 17:06:27
- Zuletzt bearbeitet 24.09.2026 16:00:04
Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with n...
CVE-2026-93765
- EPSS 0.29%
- Veröffentlicht 18.09.2026 17:01:09
- Zuletzt bearbeitet 25.09.2026 14:10:39
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method i...
CVE-2026-93758
- EPSS 0.21%
- Veröffentlicht 18.09.2026 16:56:41
- Zuletzt bearbeitet 25.09.2026 14:12:35
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause...