breaking change in findOne(ObjectId(id)) since 5.7.5 - not documented #8268
Labels
confirmed-bug
We've confirmed this is a bug in Mongoose and will fix it.
Milestone
Do you want to request a feature or report a bug?
bug
What is the current behavior?
using the following snippet:
When using
mongoose 5.7.4
it works fine and returns the inserted user.When using
mongoose 5.7.5
it returns null.This is due the a BSON vulnerability fix done in
#8222
f3eca5b
What is the expected behavior?
If it's a vulnerability, it must be fixed. But if it's a breaking change, it needs to be documented in the release notes and probably change the version to major.
What are the versions of Node.js, Mongoose and MongoDB you are using? Note that "latest" is not a version.
Node.js - 10
Mongoose: 5.7.4, 5.7.5, 5.7.6
MongoDB - 4.0
The text was updated successfully, but these errors were encountered: