- Package:
- src:node-moment
- Source:
- src:node-moment
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-18 05:35:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for node-moment. CVE-2026-17495[0]: | moment is a JavaScript date library for parsing, validating, | manipulating, and formatting dates. In versions 2.29.2 through | 2.30.1, a specially crafted non-string object passed to | moment.locale() can bypass the locale-name path-traversal guard. The | guard assumes the input is a string, so an object whose match() | method satisfies the check while its toString() returns a traversal | path reaches an internal require() call with attacker-controlled | path segments. This is an incomplete fix for CVE-2022-24785 and | primarily affects npm (server-side) users that pass user-provided | input directly to moment.locale(). The issue is fixed in moment | 2.31.0, and users should upgrade to 2.31.0 or later. As a | workaround, validate that any user-supplied input is a string before | passing it to moment.locale(). If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-17495 https://www.cve.org/CVERecord?id=CVE-2026-17495 [1] https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1148182 in node-moment reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-moment/-/commit/6627baae2d53aa60eb30fcc16485e4b8b0d41006 (this message was generated automatically) -- Greetings https://bugs.debian.org/1148182
Hello, Bug #1148182 in node-moment reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-moment/-/commit/6627baae2d53aa60eb30fcc16485e4b8b0d41006 (this message was generated automatically) -- Greetings https://bugs.debian.org/1148182
We believe that the bug you reported is fixed in the latest version of node-moment, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1148182@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Xavier Guimard <yadd@debian.org> (supplier of updated node-moment package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Fri, 18 Sep 2026 07:18:41 +0200 Source: node-moment Architecture: source Version: 2.31.0+ds1-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Xavier Guimard <yadd@debian.org> Closes: 1148182 Changes: node-moment (2.31.0+ds1-1) unstable; urgency=medium . * Team upload * Declare compliance with policy 4.7.4 * New upstream version (Closes: #1148182, CVE-2026-17495) * Refresh patch Checksums-Sha1: 79bbfa8a091801b1bdb2bc6a50be0d3076453e55 2202 node-moment_2.31.0+ds1-1.dsc 058a7afb16519353a3f28facab2ef6113730357d 331076 node-moment_2.31.0+ds1.orig.tar.xz 0654553de1c6505c5d5ec729a216d5673a57b9f1 7204 node-moment_2.31.0+ds1-1.debian.tar.xz Checksums-Sha256: e2243e1edd0617ffabc7584a573815fad3a28bf40e5d67a7c8a425d12a553ec6 2202 node-moment_2.31.0+ds1-1.dsc 402f6c7e3dbbb95f24cece100d5fddaa24c475c1f1eaa1d857c6561a9360e927 331076 node-moment_2.31.0+ds1.orig.tar.xz 9a255ee1989d72e1540b1ff518caa5c000af1ecdc9106a795f1c57335198e020 7204 node-moment_2.31.0+ds1-1.debian.tar.xz Files: 0f79d713e8d39bd6c955c82e043c1eb3 2202 javascript optional node-moment_2.31.0+ds1-1.dsc d1100b78bf16693134b61c07a7df4678 331076 javascript optional node-moment_2.31.0+ds1.orig.tar.xz 7fab9c3324d8785ef9791ebe8c00fe1b 7204 javascript optional node-moment_2.31.0+ds1-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqsyj0ACgkQ9tdMp8mZ 7uncUg/7BmYaGSYWvTA1QsBEgDa0UGCP8pA96Qb54WbebC5bosWiCbbIT/iMBZPg S87RyfGec9udeLhelPQUFSAf46COh5cH/IwcmZE0Qb8IfY4Di04q5GIDZ5v70ptn E7PC/N2jHoETaZBE13ee4c6TYnF9A4ihcN7VHy/nwhZE6Z8RHgPIF22CeytfQeuH 6tB10xbssjInMJgxvTHkYG5a1onuv89jv3bREtDFnS3GWK0KCajsoJaH85uoA/9I +GOk3y4alsqkrsi7ntII8ICiSoGh1IUzs4UyZ024xmQO8UZqEwixGKFQXnc58L0m T0WIVmx/cs4mUul377xNlg0gGJVtuSwCocvbXx81yMvLeTrusslWmVs3cCVUHDb1 FTYUuADeiqq+W9M7JPreDoSCwng/6hXtlMf1rXPnF0DEcSPwQs1xVFeADE44bvv+ H946VpzrgJNJNtHY0C6t8JNE8Rxvh89+bRjrorHSqLFavfme2c9iV7eomLWYQUuY WOWqW388iE05M6sVRGH5cVmemp81RlOmBK52q37Hso77BqJfoOAUSel0/CsENj+J HM2yPhRs5aoELUiQ+ZnUzJL9rnd8Eu6nHcpioC4mrIyWzfInA3fB8scU1IEfWi85 GbC/fva+4OlgwmIV92nax+eXvsbck32je2lLfEEJgsaChi13Qjk= =npcM -----END PGP SIGNATURE-----