Skip to content

8.0.13

Choose a tag to compare

@mongodb-dbx-release-bot mongodb-dbx-release-bot released this 17 Sep 22:22
· 383 commits to master since this release
4775b2a

The MongoDB Ruby team is pleased to announce version 8.0.13 of the mongoid gem - a Ruby ODM for MongoDB. This is a new patch release in the 8.0.x series of Mongoid.

Install this release using RubyGems via the command line as follows:

gem install -v 8.0.13 mongoid

Or simply add it to your Gemfile:

gem 'mongoid', '8.0.13'

Have any feedback? Click on through to MongoDB's Jira and open a new ticket to let us know what's on your mind.

Bug Fixes

Bound regular-expression execution time in in-memory queries (MONGOID-5981) (CVE-2026-93761)

Queries evaluated in memory, such as those against embedded associations, run in the calling thread and can spend an unbounded amount of CPU matching regular expressions. A single in-memory query is now limited by Mongoid.in_memory_regexp_time_limit (default 5.0 seconds); exceeding the limit raises Mongoid::Errors::InMemoryRegexpTimeout.

Resolve nested attribute ids within the caller's association (MONGOID-5992) (CVE-2026-93758)

An id given in nested attributes is now resolved within the association the attributes are being applied to, rather than falling back to a collection-wide lookup that ignored default scopes. A document that is not part of that association raises Mongoid::Errors::DocumentNotFound, and a request to destroy a document that is not in the association is ignored. The new Mongoid.allow_reparenting_via_nested_attributes option (default false) restores the previous reparenting behavior when set to true.

Reject the string form of where under the query operator guard (MONGOID-5993) (

CVE-2026-93759)

A String passed to #where is sent to MongoDB as a $where expression. This now raises Mongoid::Errors::InvalidQuery when Mongoid.allow_unsafe_query_operators is false (the default); the string form is allowed only when that option is enabled.

Reject JavaScript query operators at any depth (MONGOID-5994) (CVE-2026-93760)

Mongoid.allow_unsafe_query_operators now defaults to false. When it is false, the $where, $function, and $accumulator operators are rejected anywhere in a query selector. The guard covers every criterion-building method (where, find_by, or, and, nor, not, any_of, none_of, and elem_match, including chained operator overrides) and inspects nested expressions such as {'$expr' => {'$function' => ...}} in full.

Other Bug Fixes

  • In-memory queries, such as those executed against embedded associations, now read field names from the query as data rather than dispatching them as method calls on the document (MONGOID-5973) (CVE-2026-93762) (CVE-2026-93765)