CVE-2017-18214 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting the moment.js module for Node.js, specifically versions prior to 2.19.3. An unauthenticated attacker can exploit this by providing a specially crafted date string, leading to a denial of service (availability impact) on systems using the vulnerable module. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity, requiring no user interaction or privileges. The primary impact is a complete loss of availability for the affected application. Currently, there is no known public exploit code (Metasploit, Nuclei, ExploitDB) for this CVE, and it is not listed on the CISA KEV catalog, indicating it is not actively exploited in the wild. Community discussion is minimal, with only one mention found.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.19.2CPE matchmatch criteria | cpe:2.3:a:momentjs:moment:*:*:*:*:*:node.js:*:* | ||
<= 8.2.3CPE matchmatch criteria | cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2017-18214
Sep 10, 2024The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string a different vulnerability than CVE-2016-4055.
Mar 13, 2018Regular Expression Denial of Service in moment
Mar 5, 2018nodejs-moment: Regular expression denial of service
Sep 8, 2017