SEPTEMBER 24, 2026
Live Feed
Back to database
Case File

CVE-2026-93761

HIGH · CVSS 7.5 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-09-24

CyberRota Analysis

AI-Generated

An inefficient regular expression complexity vulnerability in the Mongoid library's in-memory query evaluation component can be exploited by unauthenticated attackers to trigger excessive processing, potentially leading to application unresponsiveness. Organizations utilizing Mongoid for applications that incorporate user-supplied text in pattern-matching queries should prioritize addressing this issue to mitigate the risk of denial-of-service attacks.

CVE
CVE-2026-93761
Severity
HIGH
CVSS
7.5
EPSS
0.46%

Original NVD Description

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an embedded association may become unresponsive.

Related CVEs

Other vulnerabilities affecting the same vendor(s)