Momentjs maintains a focused set of date-time manipulation libraries (Moment and Luxon) that are embedded across web applications and JavaScript environments, creating a supply-chain footprint broader than the vendor's direct CVE volume suggests. The recurring vulnerability surface centers on resource-consumption issues and path-traversal weaknesses, alongside regular-expression complexity that can degrade performance under untrusted input. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Momentjs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31129HIGH moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Spe | Jul 6, 2022 | 7.5 | 27 | NO | NO |
CVE-2022-24785HIGH Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between v | Apr 4, 2022 | 7.5 | 27 | NO | NO |
CVE-2016-4055MEDIUM The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expre | Jan 23, 2017 | 6.5 | 27 | NO | NO |
CVE-2017-18214HIGH The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055. | Mar 4, 2018 | 7.5 | 26 | NO | NO |
CVE-2023-22467HIGH Luxon is a library for working with dates and times in JavaScript. On the 1.x branch prior to 1.38.1, the 2.x branch prior to 2.5.2, and the 3.x branch on 3.2.1, Luxon's `DateTime. | Jan 4, 2023 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Momentjs.
Media articles that mention a CVE ID that affects a product developed by Momentjs — matched by CVE ID, not by vendor name.