Security Advisory

CVE-2026-2302

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-10 18:59:23
Last updated 2026-02-27 13:29:42
Assigner mongodb
State PUBLISHED

Description

Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code.