CVE-2026-102990
basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.
| CWE | CWE-1333 |
| Vendor | patrickjuchli |
| Product | basic-ftp |
| Published | Sep 30, 2026 |
| Last Updated | Sep 30, 2026 |
Get instant alerts for patrickjuchli basic-ftp
Be the first to know when new unknown vulnerabilities affecting patrickjuchli basic-ftp are published โ delivered to Slack, Telegram or Discord.