Backport $toMillis security fixes to v1 (CVE-2026-52746) - #825
Merged
mattbaileyuk merged 2 commits intoJul 30, 2026
Conversation
…#782) The factional part of the date/time seconds was being parsed and converted to an integer in order to pass to the milliseconds parameter. However, if there were more than 3 digits, then this would be more than a thousand and spill over into the seconds (and possible minutes). Moreover, if the fractional part started with a zero, this would get lost in the conversion to an integer. This commit fixes the parsing and truncates the value to max 3 digits (milliseconds is the finest resolution supported). Signed-off-by: Andrew Coleman <andrew_coleman@uk.ibm.com>
Signed-off-by: Andrew Coleman <andrew_coleman@uk.ibm.com>
mattbaileyuk
approved these changes
Jul 30, 2026
mattbaileyuk
left a comment
Member
There was a problem hiding this comment.
Thank you; the others were ported to focus on a particular issue at the time, but agree these should be ported too for that CVE
Author
|
@mattbaileyuk Could you please let me know what else should be done to release v 1.8.9 with this fix? |
Member
|
1.8.9 has now been released |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Backports the
$toMillis()security fixes for CVE-2026-52746 / GHSA-86vw-mfpg-wwv9 to thev1branch, following the precedent of #815 (released as 1.8.8).Cherry-picked from
masterwith original authorship preserved:*→?quantifier fix that removes the superlinear backtracking)$toMillis()with more than 3 digit fractional seconds (+ its test cases)Both applied cleanly to
src/datetime.js.Why
1.8.8 backported the prototype-pollution fixes but not this one, so the advisory's patched range is currently only
>= 2.2.0. Migrating v1 users to 2.x is non-trivial (sync → asyncevaluate()), and 1.x remains widely depended upon.Verification
ReDoS is neutralized. Non-matching input
'2026' + '-11'.repeat(n) + 'x'passed to$toMillis():Tests pass.
mocha test --recursive: 3330 passing. The 3 failures on this branch are identical on cleanv1(two timing-sensitive$now()/$millis()uniqueness assertions and thematchersgroup) — pre-existing, unrelated to this change.Release request
Could you cut a 1.8.9 release with this (version bump left to maintainers, as with 1.8.8), and update GHSA-86vw-mfpg-wwv9's patched versions to include
>= 1.8.9, < 2.0.0? The advisory update is what lets Dependabot/audit tooling recognize 1.8.9 as fixed.