Executive brief
Moment.js is a popular JavaScript library used for date and time manipulation in web applications and Node.js services. A ReDoS (Regular Expression Denial of Service) vulnerability in its RFC2822 date parsing allows an attacker to send specially crafted date strings that cause the application to consume excessive CPU resources, leading to service slowdowns or complete unavailability for legitimate users.
Technical details
The vulnerability is an inefficient regular expression complexity issue (CWE-1333) in Moment.js's RFC2822 date parsing logic, specifically in the code that removes legacy comments (content within parentheses) from input strings. The regex pattern exhibits quadratic (N²) complexity on certain malicious inputs. An unauthenticated attacker can trigger this by passing a specially crafted string (e.g., repeated opening parentheses) to the moment() constructor; for example, moment("(".repeat(500000)) will consume several minutes of CPU time. No authentication is required, and the attack succeeds with default parsing behavior. The vulnerability affects versions 2.18.0 through 2.29.3 and is patched in version 2.29.4.
Affected products
- Moment.js Moment.js 2.18.0 through 2.29.3
Timeline
- 2022-07-06: disclosed
- 2022-07-06: patched: Version 2.29.4 released with fix