CVE-2026-102990 Details
Description
basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.
A denial-of-service vulnerability has been identified in the basic-ftp FTP client for Node.js, specifically in versions prior to 6.2.1. The issue arises in the Unix-style directory listing parser of the Client.list() function. A malicious or compromised FTP server can craft a directory listing that forces the client to spend excessive CPU time parsing it. This is due to the regular expression used in the parser, which can backtrack across variable-length owner and group fields. As a result, a single long line can be manipulated to create a quadratic-time processing delay, effectively freezing the Node.js event loop and the entire process.
Users can upgrade to basic-ftp version 6.2.1, which addresses the vulnerability by modifying the regex used in the Unix parser to prevent backtracking that could be exploited to cause a denial-of-service.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9 | [email protected] | Source CodeVendor |
| https://github.com/patrickjuchli/basic-ftp/releases/tag/v6.2.1 | [email protected] | Release NotesVendor |
| https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1333 | Inefficient Regular Expression Complexity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| basic-ftp | <= 6.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion