Description
basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.
Published: 2026-09-30
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: CPU Denial of Service
Action: Patch Immediately
AI Analysis

Impact

basic-ftp uses a regular expression (RE_LINE) to parse Unix directory listings. An attacker can craft a line that satisfies an initial part of the pattern but not the later size and date elements, causing the expression to backtrack extensively and consume quadratic CPU time. The effect is a denial of service in the Node.js event loop, as the parsing process stalls the client application. This flaw aligns with CWE-1333 (Regular Expression Denial of Service). The attack vector is inferred to be a malicious or compromised FTP server that sends the specially crafted listing when Client.list() is invoked; a local attacker does not require elevated privileges for exploitation.

Affected Systems

All releases of patrickjuchli basic-ftp before version 6.2.1 are affected, regardless of Node.js runtime version. This includes any environment that imports the basic-ftp package and calls Client.list() against a remote FTP server.

Risk and Exploitability

With a CVSS score of 8.2, the vulnerability is considered high risk. EPSS data is not available, so the current exploitation probability cannot be quantified, but the flaw is straightforward to trigger from a remote FTP server and is not listed in the CISA KEV catalog. An attacker only needs to supply a crafted directory listing after establishing an FTP connection; no local privileges or additional exploits are required. The event loop freeze means the entire Node.js process may become unresponsive until the client terminates or restarts.

Generated by OpenCVE AI on September 30, 2026 at 22:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade basic-ftp to version 6.2.1 or later, which contains the fixed parser that no longer backtracks.
  • If upgrade is not yet possible, restrict the Client.list() operation to trusted FTP servers by filtering the server IP or applying network access controls so that untrusted connections cannot reach the client.
  • As a temporary measure, wrap the Client.list() call in a timeout or apply a pre‑parse length check to limit the size of lines processed, thereby reducing the risk of prolonged CPU consumption.

Generated by OpenCVE AI on September 30, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 30 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.
Title basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
Weaknesses CWE-1333
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T20:05:49.721Z

Reserved: 2026-09-29T20:46:08.334Z

Link: CVE-2026-102990

cve-icon Vulnrichment

Updated: 2026-09-30T20:05:24.479Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T20:17:26.140

Modified: 2026-09-30T21:17:06.307

Link: CVE-2026-102990

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T19:44:47Z

Links: CVE-2026-102990 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:45:16Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity