basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.

Project Subscriptions

Vendors Products
Patrickjuchli Subscribe
Basic-ftp Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c475-qrg2-pj4r basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 01 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Patrickjuchli
Patrickjuchli basic-ftp
Vendors & Products Patrickjuchli
Patrickjuchli basic-ftp

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 30 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.
Title basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
Weaknesses CWE-1333
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T20:05:49.721Z

Reserved: 2026-09-29T20:46:08.334Z

Link: CVE-2026-102990

cve-icon Vulnrichment

Updated: 2026-09-30T20:05:24.479Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T20:17:26.140

Modified: 2026-09-30T21:17:06.307

Link: CVE-2026-102990

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T19:44:47Z

Links: CVE-2026-102990 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T08:15:04Z

Weaknesses