Skip to content

7.6.2

Choose a tag to compare

@mongodb-dbx-release-bot mongodb-dbx-release-bot released this 17 Sep 22:23
· 647 commits to master since this release
af308fa

The MongoDB Ruby team is pleased to announce version 7.6.2 of the mongoid gem - a Ruby ODM for MongoDB. This is a new patch release in the 7.6.x series of Mongoid.

Install this release using RubyGems via the command line as follows:

gem install -v 7.6.2 mongoid

Or simply add it to your Gemfile:

gem 'mongoid', '7.6.2'

Have any feedback? Click on through to MongoDB's Jira and open a new ticket to let us know what's on your mind.

🔴 End-Of-Life Notice

After December 31, 2026, this 7.x series will no longer be supported. It will no longer receive any maintenance or security updates. If you are still running on Mongoid 7.x or earlier, please upgrade.

Bug Fixes

Bound regular-expression execution time in in-memory queries (MONGOID-5981) (CVE-2026-93761)

Queries evaluated in memory, such as those against embedded associations, run in the calling thread and can spend an unbounded amount of CPU matching regular expressions. A single in-memory query is now limited by Mongoid.in_memory_regexp_time_limit (default 5.0 seconds); exceeding the limit raises Mongoid::Errors::InMemoryRegexpTimeout.

Resolve nested attribute ids within the caller's association (MONGOID-5992) (CVE-2026-93758)

An id given in nested attributes is now resolved within the association the attributes are being applied to, rather than falling back to a collection-wide lookup that ignored default scopes. A document that is not part of that association raises Mongoid::Errors::DocumentNotFound, and a request to destroy a document that is not in the association is ignored. The new Mongoid.allow_reparenting_via_nested_attributes option (default false) restores the previous reparenting behavior when set to true.

Reject the string form of where under the query operator guard (MONGOID-5993) (

CVE-2026-93759)

A String passed to #where is sent to MongoDB as a $where expression. This now raises Mongoid::Errors::InvalidQuery when Mongoid.allow_unsafe_query_operators is false (the default); the string form is allowed only when that option is enabled.

Reject JavaScript query operators at any depth (MONGOID-5994) (CVE-2026-93760)

Mongoid.allow_unsafe_query_operators now defaults to false. When it is false, the $where, $function, and $accumulator operators are rejected anywhere in a query selector. The guard covers every criterion-building method (where, find_by, or, and, nor, not, any_of, none_of, and elem_match) and inspects nested expressions such as {'$expr' => {'$function' => ...}} in full.

Other Bug Fixes

  • In-memory queries, such as those executed against embedded associations, now read field names from the query as data rather than dispatching them as method calls on the document (MONGOID-5973) (CVE-2026-93762) (CVE-2026-93765)