StackRadar

CVE-2022-31129

High

Advisory

Published 6 Jul 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.052
92nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
121
of 17,781 indexed, latest versions
Container images
124
deployed by those charts
Fix available
1 of 1
affected package

Moment.js vulnerable to Inefficient Regular Expression Complexity

Carried by container images the latest versions of 121 of 17,781 indexed charts deploy, on 124 images.

Affected packageAffected versionsFixed inImages
momentnpm2.19.4, 2.21.0, 2.22.2, 2.24.0+8 more2.29.4124
OSV records
GHSA-wc69-rhjr-hc9g

Charts affected

121 by stars
ChartLatestAffected imagesRadar Score
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
moment@2.29.1
2.29.4

Open the chart page →

27,465
ferdi-serverobeoneVerified publisher1.0.31 of 2See more

ferdi-server obeone 1.0.3

1 of the 2 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
getferdi/ferdi-server:1.3.26e620b85afaa
moment@2.24.0
2.29.4

Open the chart page →

1,866
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
moment@2.29.1
2.29.4

Open the chart page →

9,968
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
moment@2.27.0
2.29.4

Open the chart page →

36,215
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
moment@2.29.1
2.29.4

Open the chart page →

28,484
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
moment@2.29.1
2.29.4

Open the chart page →

5,215
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
moment@2.29.1
2.29.4

Open the chart page →

7,413
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
moment@2.29.1
2.29.4

Open the chart page →

3,638
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
moment@2.29.1
2.29.4

Open the chart page →

2,460
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
moment@2.29.1
2.29.4

Open the chart page →

3,228
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
moment@2.29.1
2.29.4

Open the chart page →

2,121
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
moment@2.29.1
2.29.4

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
moment@2.29.1
2.29.4

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
moment@2.29.1
2.29.4

Open the chart page →

3,881
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
moment@2.24.0
2.29.4

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
moment@2.29.1
2.29.4

Open the chart page →

3,576
thingsboardthingsboardVerified publisher0.1.32 of 12See more

thingsboard thingsboard 0.1.3

2 of the 12 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
thingsboard/tb-js-executor:3.4.113e1eadf8ace
moment@2.29.3
2.29.4
thingsboard/tb-web-ui:3.4.157f98ed53b3d
moment@2.29.3
2.29.4

Open the chart page →

25,394
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
moment@2.24.0
2.29.4

Open the chart page →

2,559
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
moment@2.29.1
2.29.4

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
moment@2.27.0
2.29.4

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-31129.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
moment@2.24.0
2.29.4

Open the chart page →

5,806

Container images carrying it

124 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
moment@2.29.1
2.29.4
5
oscarsotosanchez/server:v1.06e2e1279126b
moment@2.29.1
2.29.4
4
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
moment@2.29.1
2.29.4
3
pantsel/konga:latestc8172b75607d
moment@2.25.1
2.29.4
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
moment@2.24.0
2.29.4
2
governify/assets-manager:v1.4.12987672448c7
moment@2.24.0
2.29.4
2
governify/director:v1.4.0608c6940bb98
moment@2.29.1
2.29.4
2
governify/registry:v3.4.0d3f37f4f8168
moment@2.29.1
2.29.4
2
governify/render:v2.2.0daeca1ce28e6
moment@2.29.1
2.29.4
2
governify/reporter:v2.2.038595913458f
moment@2.29.1
2.29.4
2
gradiant/open5gs-webui:2.7.5fbd10c017541
moment@2.22.2
2.29.4
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
moment@2.29.1
2.29.4
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
moment@2.27.0
2.29.4
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
moment@2.29.1
2.29.4
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
moment@2.27.0
2.29.4
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
moment@2.24.0
2.29.4
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
moment@2.29.1
2.29.4
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
moment@2.24.0
2.29.4
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
moment@2.22.2
2.29.4
1
arturisimo/server-urjc:v1.0d8dc4430531e
moment@2.29.2
2.29.4
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
moment@2.29.1
2.29.4
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
moment@2.28.0
2.29.4
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
moment@2.29.1
2.29.4
1
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
moment@2.22.2
2.29.4
1
catalysm/csmm:latestf003b35f54d9
moment@2.29.1
2.29.4
1
conduction/conduction-ui-app:devd591f5e6f2a9
moment@2.29.1
2.29.4
1
daskdev/dask-notebook:1.1.0052630f5ca04
moment@2.21.0
2.29.4
1
datarhei/restreamer:0.6.4655e12f9eeed
moment@2.24.0
2.29.4
1
enketo/enketo-express:3.0.4dcad9c2273f6
moment@2.29.1
2.29.4
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
moment@2.19.4
2.29.4
1
fiware/iotagent-ul:1.14.0fe11f55a926d
moment@2.28.0
2.29.4
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
moment@2.22.2
2.29.4
1
getferdi/ferdi-server:1.3.26e620b85afaa
moment@2.24.0
2.29.4
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
moment@2.29.1
2.29.4
1
gristlabs/grist:0.7.96e71b1914a7e
moment@2.29.1
2.29.4
1
henrywhitaker3/speedtest-tracker:latest47159a940229
moment@2.29.1
2.29.4
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
moment@2.29.1
2.29.4
1
hugohg34/server:0.0.2503e5d8960ff
moment@2.29.2
2.29.4
1
i4trust/pdc-portal:2.0.03e77858e1219
moment@2.29.1
2.29.4
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
moment@2.24.0
2.29.4
1
ibmcom/microclimate-portal:latested5505e5c7ec
moment@2.21.0
2.29.4
1
ibmcom/microclimate-theia:lateste17bdccc5030
moment@2.21.0
2.29.4
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
moment@2.24.0
2.29.4
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
moment@2.29.1
2.29.4
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
moment@2.29.1
2.29.4
1
jayfong/yapi:1.10.2163e5d621910
moment@2.29.1
2.29.4
1
joplin/server:3.0-beta52af57880c0e
moment@2.29.1
2.29.4
1
joplin/server:2.14.2-betab87564ef34e9
moment@2.29.1
2.29.4
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
moment@2.29.1
2.29.4
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
moment@2.29.1
2.29.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.