← Vulnerability feed

Vulnerability record · CVE-2016-4055 · published 23 January 2017

CVE-2016-4055: Momentjs moment uncontrolled resource consumption vulnerability

Momentjs · Moment

The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."

6.5 CVSS 3.1 Medium EPSS 9.9% · top 4.6% CWE-400 · Uncontrolled resource consumption
6.5CVSS 3.1 base score, v2 7.8
9.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
18References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2016/04/20/11 Mailing ListThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html PatchThird Party Advisory
http://www.securityfocus.com/bid/95849 Third Party AdvisoryVDB Entry
https://lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731%40%3Cdev.flink.apache.org%
https://lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49%40%3Cuser.flink.apache.org
https://lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2%40%3Cuser.flink.apache.org
https://lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854%40%3Cuser.flink.apache.org
https://nodesecurity.io/advisories/55 Broken LinkExploitVendor Advisory
https://www.tenable.com/security/tns-2019-02 PatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2016/04/20/11 Mailing ListThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html PatchThird Party Advisory
http://www.securityfocus.com/bid/95849 Third Party AdvisoryVDB Entry
https://lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731%40%3Cdev.flink.apache.org%
https://lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49%40%3Cuser.flink.apache.org
https://lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2%40%3Cuser.flink.apache.org
https://lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854%40%3Cuser.flink.apache.org
https://nodesecurity.io/advisories/55 Broken LinkExploitVendor Advisory
https://www.tenable.com/security/tns-2019-02 PatchThird Party Advisory

Track CVE-2016-4055 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2019-17558Apache Solr VelocityResponseWriter template injection enables remote code executionApache Solr 5.0.0 through 8.3.1 renders Velocity templates through VelocityResponseWriter, and attacker-supplied templates can execute code. Paramete…KEVEPSS 99%analysed10.0CVE-2018-14721Fasterxml jackson-databind server-side request forgery (ssrf) vulnerabilityFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …EPSS 10%9.8CVE-2022-23852Libexpat project libexpat integer overflow vulnerabilityExpat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.EPSS 4.6%9.8CVE-2022-22822Libexpat project libexpat integer overflow vulnerabilityaddBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.EPSS 4.8%9.8CVE-2022-22823Libexpat project libexpat integer overflow vulnerabilitybuild_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.EPSS 3.4%9.8CVE-2022-22824Libexpat project libexpat integer overflow vulnerabilitydefineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.EPSS 3.4%9.8CVE-2021-23450Linuxfoundation dojo prototype pollution vulnerabilityAll versions of package dojo are vulnerable to Prototype Pollution via the setObject function.EPSS 30%9.8CVE-2021-42575Owasp java html sanitizer vulnerabilityThe OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2016-4055), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.