high
CVE-2022-31129
moment regular-expression denial of service parsing a long attacker-supplied date string
- Severity
- high
- Affected product
- moment
- Affected versions
- moment ≥ 2.18.0, < 2.29.4
- Fixed in
- moment 2.29.4
- Added to NewScan
- 2026-07-30
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints moment from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →