#1147409 ruby-mongo: CVE-2026-88030

Package:
src:ruby-mongo
Source:
src:ruby-mongo
Submitter:
Salvatore Bonaccorso
Date:
2026-09-14 16:51:02 UTC
Severity:
normal
Tags:
#1147409#5
Date:
2026-09-11 15:18:53 UTC
From:
To:
Hi,

The following vulnerability was published for ruby-mongo.

CVE-2026-88030[0]:
| Improper neutralization of special elements in data query logic in
| the GridFS component of the MongoDB Ruby Driver can cause a caller-
| supplied structured file identifier to be interpreted as a query
| condition rather than as a literal identifier. An authenticated user
| who can influence the identifier passed by an affected application
| may obtain stored file content beyond the intended target or cause
| all GridFS file chunks in the affected bucket to be removed,
| rendering stored file content unreadable.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-88030
https://www.cve.org/CVERecord?id=CVE-2026-88030
[1] https://jira.mongodb.org/browse/RUBY-3941
[2] https://github.com/mongodb/mongo-ruby-driver/commit/ed62bb56c2e24c79113709331862d0aa3da74c6d

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1147409#8
Date:
2026-09-14 16:30:47 UTC
From:
To:
Hello,

Bug #1147409 in ruby-mongo reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/ruby-team/ruby-mongo/-/commit/85e480da2539ff82d24933425c664d024c30ad50

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1147409

#1147409#15
Date:
2026-09-14 16:49:24 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
ruby-mongo, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147409@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon Quigley <tsimonq2@debian.org> (supplier of updated ruby-mongo package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 14 Sep 2026 11:30:07 -0500
Source: ruby-mongo
Architecture: source
Version: 2.26.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Ruby Team <pkg-ruby-extras-maintainers@lists.alioth.debian.org>
Changed-By: Simon Quigley <tsimonq2@debian.org>
Closes: 1147409
Changes:
 ruby-mongo (2.26.0-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release (Closes: #1147409).
     - Fixes CVE-2026-88030.
Checksums-Sha1:
 82ee8d051fc09a721ea11bcc6fc9f68efa654774 2034 ruby-mongo_2.26.0-1.dsc
 86f7f3add5981a9a856e0cea06ffa4e0cb32b974 1650824 ruby-mongo_2.26.0.orig.tar.gz
 8a5c4e67b272c870ec4e06e83b5f3926e6caeba9 2864 ruby-mongo_2.26.0-1.debian.tar.xz
 e02f5b3300750a8ea1e7dabcdb99a7710554bde5 7401 ruby-mongo_2.26.0-1_source.buildinfo
Checksums-Sha256:
 485ebcf4cb139776ba49ae9942b4d444fa08697f370117464f8e5852fec920c2 2034 ruby-mongo_2.26.0-1.dsc
 68754d4e5914bad806200041b96b250732f09f8cc13655f636e4639d10382f14 1650824 ruby-mongo_2.26.0.orig.tar.gz
 03e8e7a5466152a59a11c82af9c6776a01228db1d15839fdbf91d2562d73378a 2864 ruby-mongo_2.26.0-1.debian.tar.xz
 9bd6e536d4ecec709b5fa2387888642079ba8854d7c1e26b5268adf0fad41473 7401 ruby-mongo_2.26.0-1_source.buildinfo
Files:
 126ec36be7d5c903c5534eefd7134215 2034 ruby optional ruby-mongo_2.26.0-1.dsc
 781275464ad4f49b6c7cce38f8d0d8cc 1650824 ruby optional ruby-mongo_2.26.0.orig.tar.gz
 4cb84cadf1ef4e38491bf21989d39459 2864 ruby optional ruby-mongo_2.26.0-1.debian.tar.xz
 16bad3e452b6d238701169fba2b813d0 7401 ruby optional ruby-mongo_2.26.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXHq+og+GMEWcyMi14n8s+EWML6QFAmqoITIACgkQ4n8s+EWM
L6S0NA/+MWDmZW4AyAPgnQhUWYuovH/Z4YmsndY3Mq7DGgXXieZOM2tuUJxCLmcJ
5HTmnnCEt/PGrJ0Mrh1FbNu8FV2KYjw6TNy8avisvo3FbQ8f37yAYi64fz/JxOFS
/wgNXYBsk5BC2ZMr1zMKXZccJ7fXvqgQ3F4d4s0xohz01chjpNbvRDXnOZrn4SpM
IrtBVRQce7GrZz14965TPrYunc3xsSJKdcqgs1zmyhrjBcAv68epZSKHKnHYfrd3
66GxrcYkIU9aIB5Z1Z0/kSHmYg7ncgYY2ugznc1NzEQg7XZNqdw0RjFGxt2XgoZF
PPbxzR+V211uuNnmsAamznSfVLs3HfyW/Df7Iwowb3CYInvmF/G4bYYtrkh5rLn0
QReHdaN21doUMVb9H0POomzSHfR/auGW90/WtN6/7XVCK7w/d6MmyYjqFts/nRxW
gEKEohKHaiA5sOmyPGXRPhMKwA5vbk7I5OglXxlfESxj7uiA86RHY+qGNG/8UakV
gMVBCeTsck0xHxrRhfl94EL2i5m9/WdoseJZyqGRdIn5FDxp+0CHOQMKcJM3Vsf/
Tlst5M1/nVvlq+39uO5KW8kfI8dK9rhUQjiLxiDk26OnQTMn1Orbq/kOAoZKIx9g
FNOMa3becLCs/u16/9QxN1rsx8tyMxnPYExCRKhG5qt5leDydyU=
=OASi
-----END PGP SIGNATURE-----