Vulnerability DatabaseCVE-2026-102990

CVE-2026-102990: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-102990 is a Denial of Service vulnerability caused by inefficient regular expression complexity (ReDoS) in the basic-ftp Node.js FTP client library. The RE_LINE regex in src/parseListUnix.ts exhibits quadratic backtracking when parsing crafted Unix-style directory listings, allowing a malicious or compromised FTP server to freeze the Node.js event loop. All versions of basic-ftp up to and including 6.2.0 are affected; the issue was fixed in version 6.2.1, released August 27, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is CWE-1333 (Inefficient Regular Expression Complexity), specifically catastrophic backtracking in the RE_LINE regular expression within src/parseListUnix.ts. The regex contains two adjacent unbounded variable-length groups — (\S+(?:\s\S+)*) for owner name and (\S+(?:\s\S+)*) for group name — followed by a required numeric size field. When a crafted line has a valid Unix listing prefix but no valid size/date fields, the regex engine exhaustively tries every possible token split between the two groups before failing, resulting in O(n²) CPU cost relative to line length. Additionally, parseList() selects the parser based only on the last non-blank line, so an attacker can place a valid Unix-format line at the end of the listing to trigger the Unix parser, while an earlier crafted line causes the backtracking. The DOS-style parser in parseListDOS.ts was also found to have a similar unanchored regex and was patched simultaneously (GitHub Advisory, Fix Commit).

Impact

A malicious or compromised FTP server can send a single crafted directory listing that freezes the entire Node.js event loop for seconds to minutes — or longer — depending on the crafted line length. The PoC demonstrates that a 128 KB malicious line blocks the event loop for approximately 39 seconds, and since maxListingBytes defaults to 40 MB, a single line could block the process for tens of minutes. During this freeze, no other callbacks, timers, or requests are processed, resulting in complete denial of service of the application. There is no confidentiality or integrity impact; the vulnerability is limited to availability (GitHub Advisory).

Exploitability

A complete, runnable proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating event loop freezing with a crafted FTP server and client setup. The exploit is classified as automatable (NVD SSVC: automatable: yes) and requires no user interaction, though it does require the client to authenticate to the attacker-controlled server (credentials are supplied by the application). There is no evidence of in-the-wild exploitation at this time, and the EPSS score is 0.0. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Set up a malicious FTP server: The attacker operates or compromises an FTP server and implements a minimal FTP protocol handler (responding to USER, PASS, FEAT, EPSV, and LIST commands) using a framework such as Node.js net.createServer().
  2. Craft the malicious directory listing payload: Construct a listing with two lines — a malicious first line consisting of a valid Unix prefix (-rw-r--r-- 1 ) followed by a large number of repeated a tokens (e.g., 128 KB worth) ending with ! (no valid size/date field), and a normal valid Unix-format line as the final line (e.g., -rw-r--r-- 1 owner group 42 Jan 1 2020 file.txt).
  3. Lure the client to connect: The target application must be configured or tricked into connecting to the attacker's FTP server and calling Client.list().
  4. Serve the crafted listing: When the client issues EPSV and LIST commands, the server responds with the crafted directory listing over the data connection.
  5. Trigger quadratic backtracking: The parseList() function selects the Unix parser based on the valid final line, then applies RE_LINE to every line including the malicious one. The regex engine backtracks across all possible owner/group token splits before failing, consuming O(n²) CPU time.
  6. Event loop freeze achieved: The Node.js event loop is blocked for the duration of the regex backtracking (e.g., ~39 seconds for 128 KB, potentially tens of minutes for larger payloads), causing complete denial of service of the application (GitHub Advisory).

Indicators of compromise

  • Network: Outbound FTP connections (port 21 or non-standard ports) from Node.js application servers to unexpected or newly observed FTP server IPs; unusually large FTP LIST command responses (hundreds of KB to MB in a single line).
  • Process: Node.js process CPU usage spiking to 100% on a single core for an extended period (seconds to minutes) during or after an FTP list() call; application heartbeat/health check timeouts coinciding with FTP operations.
  • Logs: Application logs showing Client.list() calls that do not return within expected timeframes; FTP session logs recording connections to untrusted or newly configured FTP server addresses; absence of timer/interval callbacks firing during an FTP listing operation.
  • File System: No direct file system artifacts are expected, as this is a CPU-based DoS with no code execution component (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade basic-ftp to version 6.2.1 or later, which anchors the RE_LINE regex and bounds the owner/group name quantifiers to a maximum of 8 words each ({0,7}), eliminating the quadratic backtracking (Fix Commit, Release v6.2.1). As a workaround for applications that cannot immediately upgrade, restrict FTP client connections to known, trusted FTP servers only, and implement network-level controls to prevent connections to arbitrary or attacker-controlled FTP endpoints. Organizations should audit all Node.js applications using basic-ftp <= 6.2.0 and prioritize patching for any that connect to externally controlled or potentially compromised FTP servers (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher NotAFlightRisk and disclosed via GitHub Security Advisory GHSA-c475-qrg2-pj4r on August 27, 2026. The advisory notes a similar prior vulnerability (GHSA-rp42-5vxx-qpwr) in the same Client.list() function, also rated High, suggesting a pattern of parser security issues in the library. Red Hat has tracked the issue as Deferred in their CVE database. No significant broader media coverage or social media discussion has been identified at this time (GitHub Advisory, Red Hat CVE).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

sid

node-proxy-agents

Affected

trixie

node-proxy-agents

Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

grafana.src

Affected

Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-mcm9-63f2-9j32HIGH8.2
  • JavaScript logoJavaScript
  • devalue
NoYesOct 01, 2026
GHSA-x5rw-q4pp-hg5gHIGH8.2
  • JavaScript logoJavaScript
  • devalue
NoYesOct 01, 2026
GHSA-hx4r-w6wj-j8fgMEDIUM6.3
  • JavaScript logoJavaScript
  • devalue
NoYesOct 01, 2026
GHSA-4q55-j62x-fr9hMEDIUM6.3
  • JavaScript logoJavaScript
  • devalue
NoYesOct 01, 2026
GHSA-wf3x-273g-mvxvLOW2.3
  • JavaScript logoJavaScript
  • devalue
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management