CVE-2026-2302: MongoDB Inc MongoDB Ruby Driver
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code.
Affected products
- MongoDB Inc MongoDB Ruby Driver: from 7.0.0, up to and including 7.6.1; from 8.0.0, up to and including 8.0.12; from 8.1.0, up to and including 8.1.12; from 9.0.0, up to and including 9.0.10
Published 2026-02-10. Last modified 2026-06-17.