CVE-2026-2302: MongoDB Inc MongoDB Ruby Driver

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code.

Affected products

  • MongoDB Inc MongoDB Ruby Driver: from 7.0.0, up to and including 7.6.1; from 8.0.0, up to and including 8.0.12; from 8.1.0, up to and including 8.1.12; from 9.0.0, up to and including 9.0.10

Published 2026-02-10. Last modified 2026-06-17.