Bug 2533595 (CVE-2026-17495)

Summary: CVE-2026-17495 moment: Moment: Path Traversal via crafted non-string input to locale function
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akostadi, amasferr, amctagga, anjoseph, anthomas, anujha, aoconnor, aschwart, asoldano, aszczucz, ataylor, bbaranow, bmaxwell, bniver, boliveir, brasmith, bstansbe, cdrage, cochase, csuconic, dbruscin, dlofthou, dmayorov, doconnor, dranck, drichtar, dschmidt, eborisov, ehelms, ehugonne, ewittman, flucifre, fmariani, ggainey, gmalinko, gmeno, gparvin, groman, gtully, istudens, ivassile, iweiss, janstey, jbalunas, jlanda, jlledo, jpasqual, jprabhak, jsherman, juwatts, jwon, kaycoth, kshier, kvanderr, lball, lchilton, mbenjamin, mcarlett, mdellweg, mhackett, mhulan, mosmerov, mposolda, mstipich, msvehla, ngough, nipatil, nmoumoul, nwallace, osousa, pantinor, pberan, pcreech, pdelbell, pesilva, pjindal, pmackay, rchan, rexwhite, rgemmell, rgodfrey, rhaigner, rhel-process-autobot, rkubis, rmartinc, rstancel, rstepani, rushinde, sfeifer, simaishi, smallamp, sostapov, ssilvert, stcannon, sthirugn, sthorger, tbish, tcunning, thjenkin, tlavocat, tmalecek, tsedmik, tsze, vdosoudi, vereddy, veshanka, vmuzikar, watson-tool-maintainers, wtam, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in moment, a JavaScript library for handling dates. A remote attacker could exploit this vulnerability by providing a specially crafted input to the `moment.locale()` function. This input, which is not a standard text string, can bypass security checks designed to prevent unauthorized access to files. As a result, an attacker could potentially manipulate file paths, leading to unintended file access or the execution of malicious code on the server.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2537785, 2537786, 2537787, 2537788, 2537789, 2537790, 2537791, 2537792, 2537793, 2537794, 2537795, 2537796, 2537797    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-15 05:51:27 UTC
moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale().