Your message dated Fri, 18 Sep 2026 05:34:00 +0000
with message-id <[email protected]>
and subject line Bug#1148182: fixed in node-moment 2.31.0+ds1-1
has caused the Debian Bug report #1148182,
regarding node-moment: CVE-2026-17495
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1148182: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1148182
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-moment
Version: 2.30.1+ds1-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-moment.

CVE-2026-17495[0]:
| moment is a JavaScript date library for parsing, validating,
| manipulating, and formatting dates. In versions 2.29.2 through
| 2.30.1, a specially crafted non-string object passed to
| moment.locale() can bypass the locale-name path-traversal guard. The
| guard assumes the input is a string, so an object whose match()
| method satisfies the check while its toString() returns a traversal
| path reaches an internal require() call with attacker-controlled
| path segments. This is an incomplete fix for CVE-2022-24785 and
| primarily affects npm (server-side) users that pass user-provided
| input directly to moment.locale(). The issue is fixed in moment
| 2.31.0, and users should upgrade to 2.31.0 or later. As a
| workaround, validate that any user-supplied input is a string before
| passing it to moment.locale().


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-17495
    https://www.cve.org/CVERecord?id=CVE-2026-17495
[1] https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: node-moment
Source-Version: 2.31.0+ds1-1
Done: Xavier Guimard <[email protected]>

We believe that the bug you reported is fixed in the latest version of
node-moment, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-moment package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 18 Sep 2026 07:18:41 +0200
Source: node-moment
Architecture: source
Version: 2.31.0+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1148182
Changes:
 node-moment (2.31.0+ds1-1) unstable; urgency=medium
 .
   * Team upload
   * Declare compliance with policy 4.7.4
   * New upstream version (Closes: #1148182, CVE-2026-17495)
   * Refresh patch
Checksums-Sha1: 
 79bbfa8a091801b1bdb2bc6a50be0d3076453e55 2202 node-moment_2.31.0+ds1-1.dsc
 058a7afb16519353a3f28facab2ef6113730357d 331076 
node-moment_2.31.0+ds1.orig.tar.xz
 0654553de1c6505c5d5ec729a216d5673a57b9f1 7204 
node-moment_2.31.0+ds1-1.debian.tar.xz
Checksums-Sha256: 
 e2243e1edd0617ffabc7584a573815fad3a28bf40e5d67a7c8a425d12a553ec6 2202 
node-moment_2.31.0+ds1-1.dsc
 402f6c7e3dbbb95f24cece100d5fddaa24c475c1f1eaa1d857c6561a9360e927 331076 
node-moment_2.31.0+ds1.orig.tar.xz
 9a255ee1989d72e1540b1ff518caa5c000af1ecdc9106a795f1c57335198e020 7204 
node-moment_2.31.0+ds1-1.debian.tar.xz
Files: 
 0f79d713e8d39bd6c955c82e043c1eb3 2202 javascript optional 
node-moment_2.31.0+ds1-1.dsc
 d1100b78bf16693134b61c07a7df4678 331076 javascript optional 
node-moment_2.31.0+ds1.orig.tar.xz
 7fab9c3324d8785ef9791ebe8c00fe1b 7204 javascript optional 
node-moment_2.31.0+ds1-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqsyj0ACgkQ9tdMp8mZ
7uncUg/7BmYaGSYWvTA1QsBEgDa0UGCP8pA96Qb54WbebC5bosWiCbbIT/iMBZPg
S87RyfGec9udeLhelPQUFSAf46COh5cH/IwcmZE0Qb8IfY4Di04q5GIDZ5v70ptn
E7PC/N2jHoETaZBE13ee4c6TYnF9A4ihcN7VHy/nwhZE6Z8RHgPIF22CeytfQeuH
6tB10xbssjInMJgxvTHkYG5a1onuv89jv3bREtDFnS3GWK0KCajsoJaH85uoA/9I
+GOk3y4alsqkrsi7ntII8ICiSoGh1IUzs4UyZ024xmQO8UZqEwixGKFQXnc58L0m
T0WIVmx/cs4mUul377xNlg0gGJVtuSwCocvbXx81yMvLeTrusslWmVs3cCVUHDb1
FTYUuADeiqq+W9M7JPreDoSCwng/6hXtlMf1rXPnF0DEcSPwQs1xVFeADE44bvv+
H946VpzrgJNJNtHY0C6t8JNE8Rxvh89+bRjrorHSqLFavfme2c9iV7eomLWYQUuY
WOWqW388iE05M6sVRGH5cVmemp81RlOmBK52q37Hso77BqJfoOAUSel0/CsENj+J
HM2yPhRs5aoELUiQ+ZnUzJL9rnd8Eu6nHcpioC4mrIyWzfInA3fB8scU1IEfWi85
GbC/fva+4OlgwmIV92nax+eXvsbck32je2lLfEEJgsaChi13Qjk=
=npcM
-----END PGP SIGNATURE-----

Attachment: pgpVzDwP8OK9g.pgp
Description: PGP signature


--- End Message ---

Reply via email to