CVE-2026-102990EPSS p28.6%
CVE-2026-102990CVE-2026-102990
Description
basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.
Scoring
| EPSS | 0.37% probability of exploitation · percentile 28.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |