Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102990— basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)

Quick assessment

Affected
patrickjuchli basic-ftp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

basic-ftp 是 Node.js 的 FTP 客户端。在 6.2.1 版本之前,恶意或已被攻陷的 FTP 服务器可以迫使 在解析目录列表时消耗二次方级的 CPU 时间。这是因为 中的 正则表达式在遇到具有有效前缀但无法满足后续文件大小和日期字段的长 Unix 风格行时,会在相邻的可变长度所有者(owner)和组(group)字段之间发生回溯。 函数会根据最后一个非空行选择解析器,并将该解析器应用于所有行。因此,一个正常的最后一行可能会选中 Unix 解析器,而之前精心构造的行则会阻塞 Node.js 事件循环

CVSS 8.2 · High

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102990

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
Source: CVE Program / CVE List V5
Vulnerability Description
basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1333
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
patrickjuchli basic-ftp < 6.2.1 -

II. Public POCs for CVE-2026-102990

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102990

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-102990 (1)

Vendor Advisories for CVE-2026-102990 (1)

Vendor Pages for CVE-2026-102990 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102990

No comments yet


Leave a comment