#1148182 node-moment: CVE-2026-17495

Package:
src:node-moment
Source:
src:node-moment
Submitter:
Salvatore Bonaccorso
Date:
2026-09-18 05:35:02 UTC
Severity:
normal
Tags:
#1148182#5
Date:
2026-09-17 20:55:31 UTC
From:
To:
Hi,

The following vulnerability was published for node-moment.

CVE-2026-17495[0]:
| moment is a JavaScript date library for parsing, validating,
| manipulating, and formatting dates. In versions 2.29.2 through
| 2.30.1, a specially crafted non-string object passed to
| moment.locale() can bypass the locale-name path-traversal guard. The
| guard assumes the input is a string, so an object whose match()
| method satisfies the check while its toString() returns a traversal
| path reaches an internal require() call with attacker-controlled
| path segments. This is an incomplete fix for CVE-2022-24785 and
| primarily affects npm (server-side) users that pass user-provided
| input directly to moment.locale(). The issue is fixed in moment
| 2.31.0, and users should upgrade to 2.31.0 or later. As a
| workaround, validate that any user-supplied input is a string before
| passing it to moment.locale().


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-17495
https://www.cve.org/CVERecord?id=CVE-2026-17495
[1] https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148182#8
Date:
2026-09-18 05:22:58 UTC
From:
To:
Hello,

Bug #1148182 in node-moment reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-moment/-/commit/6627baae2d53aa60eb30fcc16485e4b8b0d41006

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148182

#1148182#13
Date:
2026-09-18 05:22:57 UTC
From:
To:
Hello,

Bug #1148182 in node-moment reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-moment/-/commit/6627baae2d53aa60eb30fcc16485e4b8b0d41006

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148182

#1148182#18
Date:
2026-09-18 05:34:00 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
node-moment, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148182@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-moment package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 18 Sep 2026 07:18:41 +0200
Source: node-moment
Architecture: source
Version: 2.31.0+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1148182
Changes:
 node-moment (2.31.0+ds1-1) unstable; urgency=medium
 .
   * Team upload
   * Declare compliance with policy 4.7.4
   * New upstream version (Closes: #1148182, CVE-2026-17495)
   * Refresh patch
Checksums-Sha1:
 79bbfa8a091801b1bdb2bc6a50be0d3076453e55 2202 node-moment_2.31.0+ds1-1.dsc
 058a7afb16519353a3f28facab2ef6113730357d 331076 node-moment_2.31.0+ds1.orig.tar.xz
 0654553de1c6505c5d5ec729a216d5673a57b9f1 7204 node-moment_2.31.0+ds1-1.debian.tar.xz
Checksums-Sha256:
 e2243e1edd0617ffabc7584a573815fad3a28bf40e5d67a7c8a425d12a553ec6 2202 node-moment_2.31.0+ds1-1.dsc
 402f6c7e3dbbb95f24cece100d5fddaa24c475c1f1eaa1d857c6561a9360e927 331076 node-moment_2.31.0+ds1.orig.tar.xz
 9a255ee1989d72e1540b1ff518caa5c000af1ecdc9106a795f1c57335198e020 7204 node-moment_2.31.0+ds1-1.debian.tar.xz
Files:
 0f79d713e8d39bd6c955c82e043c1eb3 2202 javascript optional node-moment_2.31.0+ds1-1.dsc
 d1100b78bf16693134b61c07a7df4678 331076 javascript optional node-moment_2.31.0+ds1.orig.tar.xz
 7fab9c3324d8785ef9791ebe8c00fe1b 7204 javascript optional node-moment_2.31.0+ds1-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqsyj0ACgkQ9tdMp8mZ
7uncUg/7BmYaGSYWvTA1QsBEgDa0UGCP8pA96Qb54WbebC5bosWiCbbIT/iMBZPg
S87RyfGec9udeLhelPQUFSAf46COh5cH/IwcmZE0Qb8IfY4Di04q5GIDZ5v70ptn
E7PC/N2jHoETaZBE13ee4c6TYnF9A4ihcN7VHy/nwhZE6Z8RHgPIF22CeytfQeuH
6tB10xbssjInMJgxvTHkYG5a1onuv89jv3bREtDFnS3GWK0KCajsoJaH85uoA/9I
+GOk3y4alsqkrsi7ntII8ICiSoGh1IUzs4UyZ024xmQO8UZqEwixGKFQXnc58L0m
T0WIVmx/cs4mUul377xNlg0gGJVtuSwCocvbXx81yMvLeTrusslWmVs3cCVUHDb1
FTYUuADeiqq+W9M7JPreDoSCwng/6hXtlMf1rXPnF0DEcSPwQs1xVFeADE44bvv+
H946VpzrgJNJNtHY0C6t8JNE8Rxvh89+bRjrorHSqLFavfme2c9iV7eomLWYQUuY
WOWqW388iE05M6sVRGH5cVmemp81RlOmBK52q37Hso77BqJfoOAUSel0/CsENj+J
HM2yPhRs5aoELUiQ+ZnUzJL9rnd8Eu6nHcpioC4mrIyWzfInA3fB8scU1IEfWi85
GbC/fva+4OlgwmIV92nax+eXvsbck32je2lLfEEJgsaChi13Qjk=
=npcM
-----END PGP SIGNATURE-----