CVE-2017-18214: Momentjs Moment

High severity, CVSS 7.5. EPSS: 3.6% chance of exploitation in the next 30 days.

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

Affected products

  • Momentjs Moment: up to and including 2.19.2
  • Tenable Nessus: up to and including 8.2.3

Published 2018-03-04. Last modified 2026-06-17.