CVE-2026-102990
Deferred Deferred - Pending Action

FTP Client Quadratic CPU DoS via Malicious Directory Listing

Vulnerability report for CVE-2026-102990, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
basic-ftp basic-ftp to 6.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the basic-ftp library for Node.js. It allows a malicious FTP server to cause excessive CPU usage by sending a specially crafted directory listing. The issue occurs in the Client.list() function, which uses a regular expression that backtracks across fields in Unix-style directory listings, leading to quadratic time complexity and freezing the Node.js event loop.

Detection Guidance

This vulnerability is specific to the basic-ftp library in Node.js applications. To detect it, check if your application uses basic-ftp versions prior to 6.2.1. Run 'npm list basic-ftp' in your project directory to see the installed version.

Impact Analysis

If you use a vulnerable version of basic-ftp (before 6.2.1), a malicious FTP server could freeze your application by sending a maliciously crafted directory listing. This would block the Node.js event loop, making your application unresponsive until the server disconnects or the process is terminated.

Mitigation Strategies

Upgrade the basic-ftp library to version 6.2.1 or later using 'npm install basic-ftp@latest'. If upgrading is not possible, consider replacing basic-ftp with an alternative FTP client library that is actively maintained and secure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102990. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart