Junglewise Threat Intelligence

Moment.js regular expression denial of service in duration function

Severity: info · Published 2018-07-31

Technologies: Moment.js Moment.

Executive brief

Moment.js is a popular JavaScript library for parsing, validating, and formatting dates and times. A vulnerability in the duration function allows an attacker to submit a specially crafted long string that causes excessive CPU consumption, potentially leading to service unavailability or denial of service conditions for applications relying on this library.

Technical details

This vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in the duration function of moment.js. The vulnerable component uses a regex pattern that exhibits exponential backtracking behavior when processing certain input strings, allowing an attacker to craft long strings that trigger excessive CPU consumption. The attack vector is network-based and requires no authentication—any application accepting untrusted input and passing it to the duration function is at risk. The vulnerability affects versions before 2.11.2, which includes a fix for the problematic regex pattern. This advisory was withdrawn as an accidental duplicate of CVE-2016-4055.

Affected products

  • Moment.js Moment before 2.11.2

Timeline

  • 2018-07-31: disclosed: Advisory published to GitHub Advisory Database
  • 2011-02-01: patched: Fixed in version 2.11.2
  • 2020-06-17: other: Advisory withdrawn as accidental duplicate of CVE-2016-4055