Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0326 | Luxon is a library for working with dates and times in JavaScript. On the 1.x branch prior to 1.38.1, the 2.x branch prior to 2.5.2, and the 3.x branch on 3.2.1, Luxon's `DateTime.fromRFC2822() has quadratic (N^2) complexity on some specific inputs. This causes a noticeable slowdown for inputs with lengths above 10k characters. Users providing untrusted data to this method are therefore vulnerable to (Re)DoS attacks. This issue also appears in Moment as CVE-2022-31129. Versions 1.38.1, 2.5.2, and 3.2.1 contain patches for this issue. As a workaround, limit the length of the input. |
Github GHSA |
GHSA-3xq5-wjfh-ppjc | Luxon Inefficient Regular Expression Complexity vulnerability |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T16:43:52.699Z
Reserved: 2022-12-29T03:00:40.880Z
Link: CVE-2023-22467
No data.
Status : Modified
Published: 2023-01-04T22:15:09.357
Modified: 2026-06-17T05:35:31.100
Link: CVE-2023-22467
OpenCVE Enrichment
No data.
-
CWE-1333
Inefficient Regular Expression Complexity
EUVD
Github GHSA