Skip to content

9.1.1

Latest

Choose a tag to compare

@mongodb-dbx-release-bot mongodb-dbx-release-bot released this 17 Sep 22:16
381d954

The MongoDB Ruby team is pleased to announce version 9.1.1 of the mongoid gem - a Ruby ODM for MongoDB. This is a new patch release in the 9.1.x series of Mongoid.

Install this release using RubyGems via the command line as follows:

gem install -v 9.1.1 mongoid

Or simply add it to your Gemfile:

gem 'mongoid', '9.1.1'

Have any feedback? Click on through to MongoDB's Jira and open a new ticket to let us know what's on your mind.

Bug Fixes

Bound regular-expression execution time in in-memory queries (MONGOID-5981) (CVE-2026-93761)

Queries evaluated in memory, such as those against embedded associations, run in the calling thread and can spend an unbounded amount of CPU matching regular expressions. A single in-memory query is now limited by Mongoid.in_memory_regexp_time_limit (default 5.0 seconds); exceeding the limit raises Mongoid::Errors::InMemoryRegexpTimeout.

Fix encryption schema generation for automatic encryption (MONGOID-5984) (MONGOID-5989) (CVE-2026-93764) (CVE-2026-93763)

Automatic encryption schema generation no longer loops on models that embed themselves, and it now handles polymorphic embeds_one relations and embedded schemas that carry their own encryptMetadata correctly. A model whose collection has no entry in the generated schema is no longer written without encryption: such a write raises Mongoid::Errors::NoEncryptionSchema instead of storing the field in plaintext.

Resolve nested attribute ids within the caller's association (MONGOID-5992) (CVE-2026-93758)

An id given in nested attributes is now resolved within the association the attributes are being applied to, rather than falling back to a collection-wide lookup that ignored default scopes. A document that is not part of that association raises Mongoid::Errors::DocumentNotFound, and a request to destroy a document that is not in the association is ignored. The Mongoid.allow_reparenting_via_nested_attributes option now defaults to false; set it to true to restore the previous reparenting behavior.

Reject the string form of where under the query operator guard (MONGOID-5993) (CVE-2026-93759)

A String passed to #where is sent to MongoDB as a $where expression. This now raises Mongoid::Errors::InvalidQuery when Mongoid.allow_unsafe_query_operators is false (the default); the string form is allowed only when that option is enabled.

Reject JavaScript query operators at any depth (MONGOID-5994) (CVE-2026-93760)

Mongoid.allow_unsafe_query_operators now defaults to false. When it is false, the $where, $function, and $accumulator operators are rejected anywhere in a query selector. The guard covers every criterion-building method (where, find_by, or, and, nor, not, any_of, none_of, and elem_match) and inspects nested expressions such as {'$expr' => {'$function' => ...}} in full.

Other Bug Fixes

  • In-memory queries, such as those executed against embedded associations, now read field names from the query as data rather than dispatching them as method calls on the document (MONGOID-5973) (CVE-2026-93762) (CVE-2026-93765)