
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-102990 is a Denial of Service vulnerability caused by inefficient regular expression complexity (ReDoS) in the basic-ftp Node.js FTP client library. The RE_LINE regex in src/parseListUnix.ts exhibits quadratic backtracking when parsing crafted Unix-style directory listings, allowing a malicious or compromised FTP server to freeze the Node.js event loop. All versions of basic-ftp up to and including 6.2.0 are affected; the issue was fixed in version 6.2.1, released August 27, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Red Hat CVE).
The root cause is CWE-1333 (Inefficient Regular Expression Complexity), specifically catastrophic backtracking in the RE_LINE regular expression within src/parseListUnix.ts. The regex contains two adjacent unbounded variable-length groups — (\S+(?:\s\S+)*) for owner name and (\S+(?:\s\S+)*) for group name — followed by a required numeric size field. When a crafted line has a valid Unix listing prefix but no valid size/date fields, the regex engine exhaustively tries every possible token split between the two groups before failing, resulting in O(n²) CPU cost relative to line length. Additionally, parseList() selects the parser based only on the last non-blank line, so an attacker can place a valid Unix-format line at the end of the listing to trigger the Unix parser, while an earlier crafted line causes the backtracking. The DOS-style parser in parseListDOS.ts was also found to have a similar unanchored regex and was patched simultaneously (GitHub Advisory, Fix Commit).
A malicious or compromised FTP server can send a single crafted directory listing that freezes the entire Node.js event loop for seconds to minutes — or longer — depending on the crafted line length. The PoC demonstrates that a 128 KB malicious line blocks the event loop for approximately 39 seconds, and since maxListingBytes defaults to 40 MB, a single line could block the process for tens of minutes. During this freeze, no other callbacks, timers, or requests are processed, resulting in complete denial of service of the application. There is no confidentiality or integrity impact; the vulnerability is limited to availability (GitHub Advisory).
A complete, runnable proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating event loop freezing with a crafted FTP server and client setup. The exploit is classified as automatable (NVD SSVC: automatable: yes) and requires no user interaction, though it does require the client to authenticate to the attacker-controlled server (credentials are supplied by the application). There is no evidence of in-the-wild exploitation at this time, and the EPSS score is 0.0. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Red Hat CVE).
USER, PASS, FEAT, EPSV, and LIST commands) using a framework such as Node.js net.createServer().-rw-r--r-- 1 ) followed by a large number of repeated a tokens (e.g., 128 KB worth) ending with ! (no valid size/date field), and a normal valid Unix-format line as the final line (e.g., -rw-r--r-- 1 owner group 42 Jan 1 2020 file.txt).Client.list().EPSV and LIST commands, the server responds with the crafted directory listing over the data connection.parseList() function selects the Unix parser based on the valid final line, then applies RE_LINE to every line including the malicious one. The regex engine backtracks across all possible owner/group token splits before failing, consuming O(n²) CPU time.LIST command responses (hundreds of KB to MB in a single line).list() call; application heartbeat/health check timeouts coinciding with FTP operations.Client.list() calls that do not return within expected timeframes; FTP session logs recording connections to untrusted or newly configured FTP server addresses; absence of timer/interval callbacks firing during an FTP listing operation.The primary remediation is to upgrade basic-ftp to version 6.2.1 or later, which anchors the RE_LINE regex and bounds the owner/group name quantifiers to a maximum of 8 words each ({0,7}), eliminating the quadratic backtracking (Fix Commit, Release v6.2.1). As a workaround for applications that cannot immediately upgrade, restrict FTP client connections to known, trusted FTP servers only, and implement network-level controls to prevent connections to arbitrary or attacker-controlled FTP endpoints. Organizations should audit all Node.js applications using basic-ftp <= 6.2.0 and prioritize patching for any that connect to externally controlled or potentially compromised FTP servers (GitHub Advisory).
The vulnerability was reported by security researcher NotAFlightRisk and disclosed via GitHub Security Advisory GHSA-c475-qrg2-pj4r on August 27, 2026. The advisory notes a similar prior vulnerability (GHSA-rp42-5vxx-qpwr) in the same Client.list() function, also rated High, suggesting a pattern of parser security issues in the library. Red Hat has tracked the issue as Deferred in their CVE database. No significant broader media coverage or social media discussion has been identified at this time (GitHub Advisory, Red Hat CVE).
Disponibilidade de correção em distribuições Linux principais e suas versões.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."