jira.mongodb.org
https://jira.mongodb.org/browse/MONGOID-5919 CVE-2026-2302
MEDIUM
Unsafe Reflection in Mongoid::Criteria.from_hash
Record summary
CVE-2026-2302 has a selected CVSS score of 6.9 (medium).
Description
Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MongoDB Ruby DriverBrowse MongoDB Inc / MongoDB Ruby DriverDefault status: unaffected | CVE List | 7.0.0 to ≤ 7.6.1 | affected |
| 8.0.0 to ≤ 8.0.12 | affected | ||
| 8.1.0 to ≤ 8.1.12 | affected | ||
| 9.0.0 to ≤ 9.0.10 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-2302