Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.3 Node.js & npm GHSA-c475-qrg2-pj4r CVE-2026-102990

basic-ftp: ReDoS Vulnerability in Unix Directory Listing Parser Allows Remote CPU Exhaustion

basic-ftp before 6.2.1 contains a regular expression denial of service (ReDoS) flaw in its Unix directory-listing parser. A malicious or compromised FTP server can send a crafted directory listing that causes Client.list() to consume quadratic CPU time, freezing the Node.js event loop. Fixed in 6.2.1.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A vulnerability has been disclosed in basic-ftp, a popular FTP client library for Node.js. The issue allows a malicious or compromised FTP server to cause excessive CPU consumption on the client side by returning a specially crafted directory listing, potentially freezing the entire Node.js process. The vulnerability has been assigned CVE-2026-102990 and GHSA-c475-qrg2-pj4r, and is fixed in version 6.2.1.

What Happened

A regular expression denial of service (ReDoS) vulnerability was identified in basic-ftp, an FTP client library for Node.js. The flaw resides in the Unix directory-listing parser, where a specific regular expression (RE_LINE) used in src/parseListUnix.ts can be forced into catastrophic backtracking. When a long Unix-style directory listing line has a valid prefix but fails to satisfy the later size and date fields, the regex engine spends quadratic time attempting to match adjacent variable-length owner and group fields.

Technical Cause

The root cause lies in how basic-ftp's parseList() function selects a parser. It inspects the last nonblank line of a directory listing to choose which format parser to apply, then applies that same parser to every line in the listing. This means a normal, well-formed final line can cause the Unix parser to be selected, while an earlier line in the same listing — crafted by a malicious server — triggers catastrophic backtracking in the RE_LINE expression. Because Client.list() parses every line with this selected parser, a single malicious entry anywhere in the listing is sufficient to block the Node.js event loop.

Why It Matters

Because the vulnerability can be triggered remotely by the FTP server without any authentication or user interaction beyond issuing a listing request, it poses a denial-of-service risk to any Node.js application that connects to FTP servers it does not fully control or trust. A single crafted response can freeze the event loop, effectively halting processing for the affected application until the CPU-bound operation completes or the process is restarted.

Who Is Affected

Any application using the basic-ftp npm package to connect to FTP servers is potentially affected if that server is malicious or has been compromised. This is particularly relevant for applications that connect to third-party or less-trusted FTP servers, since the attack is initiated by the server's response to a listing command.

Affected Versions

All versions of basic-ftp from 0 up to and including 6.2.0 are affected. The vulnerability is fixed in version 6.2.1.

Fixes and Mitigation

The vendor has released basic-ftp version 6.2.1, which fixes the RE_LINE backtracking issue in the Unix directory-listing parser. No other mitigations are described in the available fact package.

Recommended Action

Update the basic-ftp npm package to version 6.2.1 or later as soon as possible. Applications that connect to FTP servers outside their direct control should prioritize this update given the remote, unauthenticated nature of the trigger.

PatchBriefing score

5.3 / 10 · Medium

Official CVSS: 8.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

This issue carries a CVSS score of 8.2, driven primarily by its base severity, reflecting high availability impact with low attack complexity. The PatchBriefing score of 5.3 is lower, reflecting the absence of known exploitation, no public exploit code, and no EPSS-based indication of near-term exploitation likelihood (EPSS data in the package shows a very low probability). Contributing factors include that the vulnerability can be triggered remotely without authentication and without user interaction, though it does not affect confidentiality or integrity — only availability — and a fix is already available.

Affected versions

basic-ftp <= 6.2.0
vulnerable
≥ 6.2.1
patched

Reported fixes

The vendor has released basic-ftp version 6.2.1, which fixes the RE_LINE backtracking issue in the Unix directory-listing parser. No other mitigations are described in the available fact package.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
basic-ftp: ReDoS Vulnerability in Unix Directory Listing Parser Allows Remote CPU Exhaustion
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email