StackRadar

CVE-2022-31129

High

Advisory

Published 6 Jul 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.052
92nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
121
of 17,781 indexed, latest versions
Container images
124
deployed by those charts
Fix available
1 of 1
affected package

Moment.js vulnerable to Inefficient Regular Expression Complexity

Carried by container images the latest versions of 121 of 17,781 indexed charts deploy, on 124 images.

Affected packageAffected versionsFixed inImages
momentnpm2.19.4, 2.21.0, 2.22.2, 2.24.0+8 more2.29.4124
OSV records
GHSA-wc69-rhjr-hc9g

Charts affected

121 by stars
ChartLatestAffected imagesRadar Score
lighthouse-cicowboysysopVerified publisher9.0.01 of 1See more

lighthouse-ci cowboysysop 9.0.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
patrickhulce/lhci-server:0.8.174b4b6a3954d
moment@2.29.1
2.29.4

Open the chart page →

2,213
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
moment@2.24.0
2.29.4

Open the chart page →

5,251
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
moment@2.29.1
2.29.4
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
moment@2.29.1
2.29.4

Open the chart page →

52,919
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
moment@2.27.0
2.29.4

Open the chart page →

8,213
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
moment@2.29.1
2.29.4

Open the chart page →

5,946
kubeflowkubeflow1.6.21 of 45See more

kubeflow kubeflow 1.6.2

1 of the 45 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
moment@2.29.2
2.29.4

Open the chart page →

96,941
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
moment@2.22.2
2.29.4

Open the chart page →

9,261
audiobookshelfgeek-cookbookVerified publisher1.2.21 of 1See more

audiobookshelf geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
moment@2.29.2
2.29.4

Open the chart page →

1,959
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
moment@2.29.1
2.29.4

Open the chart page →

22,773
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
moment@2.29.1
2.29.4

Open the chart page →

3,476
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
moment@2.25.1
2.29.4

Open the chart page →

5,209
kubeviouskubevious1.2.21 of 7See more

kubevious kubevious 1.2.2

1 of the 7 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
kubevious/guard:1.2.19bf567704de2
moment@2.29.1
2.29.4

Open the chart page →

14,204
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
moment@2.22.2
2.29.4

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
moment@2.29.1
2.29.4
kobotoolbox/kpi:2.022.24dbcacc01bccd4
moment@2.27.0
2.29.4

Open the chart page →

18,517
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.261 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

1 of the 6 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
thingsboard/tb-web-ui:3.6.0d388378062cc
moment@2.29.3
2.29.4

Open the chart page →

14,566
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
moment@2.29.2
2.29.4

Open the chart page →

2,851
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
moment@2.28.0
2.29.4

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
moment@2.29.1
2.29.4

Open the chart page →

10,730
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
ghcr.io/data-fair/simple-directory:438a4f32fad82
moment@2.29.1
2.29.4

Open the chart page →

38,346
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
moment@2.29.1
2.29.4

Open the chart page →

3,925
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
moment@2.29.1
2.29.4

Open the chart page →

2,519
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
moment@2.24.0
2.29.4

Open the chart page →

4,260
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
moment@2.29.1
2.29.4

Open the chart page →

4,405
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
moment@2.29.1
2.29.4

Open the chart page →

3,444
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
moment@2.29.1
2.29.4

Open the chart page →

7,801
uptimerobotgeek-cookbookVerified publisher3.0.41 of 1See more

uptimerobot geek-cookbook 3.0.4

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
moment@2.22.2
2.29.4

Open the chart page →

1,669
youtubedl-materialgeek-cookbookVerified publisher4.4.21 of 1See more

youtubedl-material geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.23720b856bd2f
moment@2.29.1
2.29.4

Open the chart page →

4,410
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
moment@2.29.1
2.29.4

Open the chart page →

2,173
pdc-portali4trustVerified publisher2.3.21 of 1See more

pdc-portal i4trust 2.3.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
i4trust/pdc-portal:2.0.03e77858e1219
moment@2.29.1
2.29.4

Open the chart page →

2,723
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
moment@2.29.2
2.29.4

Open the chart page →

17,284
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
moment@2.22.2
2.29.4

Open the chart page →

5,300
flamerlex0.3.01 of 1See more

flame rlex 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
pawelmalak/flame:2.1.193e7b0abb603
moment@2.29.1
2.29.4

Open the chart page →

2,449
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
moment@2.24.0
2.29.4

Open the chart page →

7,517
restreamerutkuozdemirVerified publisher1.1.01 of 1See more

restreamer utkuozdemir 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
datarhei/restreamer:0.6.4655e12f9eeed
moment@2.24.0
2.29.4

Open the chart page →

2,598
scrapoxywiremindVerified publisher0.3.41 of 1See more

scrapoxy wiremind 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
wiremind/scrapoxy:lateste7048929a676
moment@2.19.4
2.29.4

Open the chart page →

2,154
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
moment@2.22.2
2.29.4

Open the chart page →

25,443
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
moment@2.25.1
2.29.4

Open the chart page →

18,277
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
moment@2.24.0
2.29.4

Open the chart page →

5,806
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
moment@2.24.0
2.29.4

Open the chart page →

4,083
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
moment@2.21.0
2.29.4

Open the chart page →

29,901
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
moment@2.19.4
2.29.4

Open the chart page →

27,417
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
moment@2.22.2
2.29.4

Open the chart page →

2,580
node-redcloudnativeapp1.2.21 of 1See more

node-red cloudnativeapp 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
nodered/node-red-docker:0.19.6-v8070643219ea2
moment@2.24.0
2.29.4

Open the chart page →

4,790
robot-shopcloud-native-toolkit1.1.13 of 12See more

robot-shop cloud-native-toolkit 1.1.1

3 of the 12 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
robotshop/rs-cart:latest388349d5cb3c
moment@2.29.1
2.29.4
robotshop/rs-catalogue:latestd545747c1b97
moment@2.29.1
2.29.4
robotshop/rs-user:latestea509182c180
moment@2.29.1
2.29.4

Open the chart page →

29,555
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
moment@2.29.1
2.29.4

Open the chart page →

12,907
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
moment@2.25.1
2.29.4

Open the chart page →

5,209
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
moment@2.29.1
2.29.4

Open the chart page →

27,550
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
moment@2.25.3
2.29.4

Open the chart page →

4,223
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
moment@2.29.1
2.29.4

Open the chart page →

24,656
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
moment@2.22.2
2.29.4

Open the chart page →

11,174

Container images carrying it

124 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
tzahi12345/youtubedl-material:4.23720b856bd2f
moment@2.29.1
2.29.4
1
ubercadence/web:v3.29.58564a5b44a6d
moment@2.29.1
2.29.4
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
moment@2.29.1
2.29.4
1
wekanteam/wekan:v4.2268a51f0327df
moment@2.27.0
2.29.4
1
wiremind/scrapoxy:lateste7048929a676
moment@2.19.4
2.29.4
1
zooz/predator:1.6f491d1f7a865
moment@2.29.2
2.29.4
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
moment@2.29.1
2.29.4
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
moment@2.29.2
2.29.4
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
moment@2.26.0
2.29.4
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
moment@2.24.0
2.29.4
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
moment@2.24.0
2.29.4
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
moment@2.22.2
2.29.4
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
moment@2.29.1
2.29.4
1
ghcr.io/leoquote/mergeable:latest451706815103
moment@2.25.3
2.29.4
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
moment@2.29.1
2.29.4
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
moment@2.29.1
2.29.4
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
moment@2.29.1
2.29.4
1
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
moment@2.24.0
2.29.4
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
moment@2.24.0
2.29.4
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
moment@2.29.1
2.29.4
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
moment@2.29.1
2.29.4
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
moment@2.29.1
2.29.4
1
quay.io/wekan/wekan:v5.65cb17600883a3
moment@2.29.1
2.29.4
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
moment@2.22.2
2.29.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.