CVE-2026-102990: 
JavaScript Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-102990 is a Denial of Service vulnerability caused by inefficient regular expression complexity (ReDoS) in the basic-ftp Node.js FTP client library. The RE_LINE regex in src/parseListUnix.ts exhibits quadratic backtracking when parsing crafted Unix-style directory listings, allowing a malicious or compromised FTP server to freeze the Node.js event loop. All versions of basic-ftp up to and including 6.2.0 are affected; the issue was fixed in version 6.2.1, released August 27, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Red Hat CVE).

Detalhes técnicos

The root cause is CWE-1333 (Inefficient Regular Expression Complexity), specifically catastrophic backtracking in the RE_LINE regular expression within src/parseListUnix.ts. The regex contains two adjacent unbounded variable-length groups — (\S+(?:\s\S+)*) for owner name and (\S+(?:\s\S+)*) for group name — followed by a required numeric size field. When a crafted line has a valid Unix listing prefix but no valid size/date fields, the regex engine exhaustively tries every possible token split between the two groups before failing, resulting in O(n²) CPU cost relative to line length. Additionally, parseList() selects the parser based only on the last non-blank line, so an attacker can place a valid Unix-format line at the end of the listing to trigger the Unix parser, while an earlier crafted line causes the backtracking. The DOS-style parser in parseListDOS.ts was also found to have a similar unanchored regex and was patched simultaneously (GitHub Advisory, Fix Commit).

Impacto

A malicious or compromised FTP server can send a single crafted directory listing that freezes the entire Node.js event loop for seconds to minutes — or longer — depending on the crafted line length. The PoC demonstrates that a 128 KB malicious line blocks the event loop for approximately 39 seconds, and since maxListingBytes defaults to 40 MB, a single line could block the process for tens of minutes. During this freeze, no other callbacks, timers, or requests are processed, resulting in complete denial of service of the application. There is no confidentiality or integrity impact; the vulnerability is limited to availability (GitHub Advisory).

Exploração

A complete, runnable proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating event loop freezing with a crafted FTP server and client setup. The exploit is classified as automatable (NVD SSVC: automatable: yes) and requires no user interaction, though it does require the client to authenticate to the attacker-controlled server (credentials are supplied by the application). There is no evidence of in-the-wild exploitation at this time, and the EPSS score is 0.0. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Red Hat CVE).

Etapas de exploração

  1. Set up a malicious FTP server: The attacker operates or compromises an FTP server and implements a minimal FTP protocol handler (responding to USER, PASS, FEAT, EPSV, and LIST commands) using a framework such as Node.js net.createServer().
  2. Craft the malicious directory listing payload: Construct a listing with two lines — a malicious first line consisting of a valid Unix prefix (-rw-r--r-- 1 ) followed by a large number of repeated a tokens (e.g., 128 KB worth) ending with ! (no valid size/date field), and a normal valid Unix-format line as the final line (e.g., -rw-r--r-- 1 owner group 42 Jan 1 2020 file.txt).
  3. Lure the client to connect: The target application must be configured or tricked into connecting to the attacker's FTP server and calling Client.list().
  4. Serve the crafted listing: When the client issues EPSV and LIST commands, the server responds with the crafted directory listing over the data connection.
  5. Trigger quadratic backtracking: The parseList() function selects the Unix parser based on the valid final line, then applies RE_LINE to every line including the malicious one. The regex engine backtracks across all possible owner/group token splits before failing, consuming O(n²) CPU time.
  6. Event loop freeze achieved: The Node.js event loop is blocked for the duration of the regex backtracking (e.g., ~39 seconds for 128 KB, potentially tens of minutes for larger payloads), causing complete denial of service of the application (GitHub Advisory).

Indicadores de compromisso

  • Network: Outbound FTP connections (port 21 or non-standard ports) from Node.js application servers to unexpected or newly observed FTP server IPs; unusually large FTP LIST command responses (hundreds of KB to MB in a single line).
  • Process: Node.js process CPU usage spiking to 100% on a single core for an extended period (seconds to minutes) during or after an FTP list() call; application heartbeat/health check timeouts coinciding with FTP operations.
  • Logs: Application logs showing Client.list() calls that do not return within expected timeframes; FTP session logs recording connections to untrusted or newly configured FTP server addresses; absence of timer/interval callbacks firing during an FTP listing operation.
  • File System: No direct file system artifacts are expected, as this is a CPU-based DoS with no code execution component (GitHub Advisory).

Mitigação e soluções alternativas

The primary remediation is to upgrade basic-ftp to version 6.2.1 or later, which anchors the RE_LINE regex and bounds the owner/group name quantifiers to a maximum of 8 words each ({0,7}), eliminating the quadratic backtracking (Fix Commit, Release v6.2.1). As a workaround for applications that cannot immediately upgrade, restrict FTP client connections to known, trusted FTP servers only, and implement network-level controls to prevent connections to arbitrary or attacker-controlled FTP endpoints. Organizations should audit all Node.js applications using basic-ftp <= 6.2.0 and prioritize patching for any that connect to externally controlled or potentially compromised FTP servers (GitHub Advisory).

Reações da comunidade

The vulnerability was reported by security researcher NotAFlightRisk and disclosed via GitHub Security Advisory GHSA-c475-qrg2-pj4r on August 27, 2026. The advisory notes a similar prior vulnerability (GHSA-rp42-5vxx-qpwr) in the same Client.list() function, also rated High, suggesting a pattern of parser security issues in the library. Red Hat has tracked the issue as Deferred in their CVE database. No significant broader media coverage or social media discussion has been identified at this time (GitHub Advisory, Red Hat CVE).

Recursos adicionais

Status correto da distribuição Linux

Disponibilidade de correção em distribuições Linux principais e suas versões.

Debian

Afetados

sid

node-proxy-agents

Afetados

trixie

node-proxy-agents

Afetados

RHEL / CentOS

Afetados

RHEL 8

Não Afetado

RHEL 9

Não Afetado

RHEL 10

grafana.src

Afetados

Origem: Este relatório foi gerado usando IA

Relacionado JavaScript Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

GHSA-gg6r-gp4c-89hpCRITICAL9.2
  • JavaScript logoJavaScript
  • trigger.dev
NãoSimOct 02, 2026
GHSA-pqxw-g93w-hj9xHIGH8.1
  • JavaScript logoJavaScript
  • trigger.dev
NãoSimOct 02, 2026
GHSA-9q4r-4842-93vwHIGH7.7
  • JavaScript logoJavaScript
  • trigger.dev
NãoSimOct 02, 2026
GHSA-fj2x-mqqp-3v2wMEDIUM5.5
  • JavaScript logoJavaScript
  • trigger.dev
NãoSimOct 02, 2026
GHSA-4672-hwv6-gq62MEDIUM5.4
  • JavaScript logoJavaScript
  • trigger.dev
NãoSimOct 02, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades