
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-102990 is a Denial of Service vulnerability caused by inefficient regular expression complexity (ReDoS) in the basic-ftp Node.js FTP client library. The RE_LINE regex in src/parseListUnix.ts exhibits quadratic backtracking when parsing crafted Unix-style directory listings, allowing a malicious or compromised FTP server to freeze the Node.js event loop. All versions of basic-ftp up to and including 6.2.0 are affected; the issue was fixed in version 6.2.1, released August 27, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Red Hat CVE).
The root cause is CWE-1333 (Inefficient Regular Expression Complexity), specifically catastrophic backtracking in the RE_LINE regular expression within src/parseListUnix.ts. The regex contains two adjacent unbounded variable-length groups — (\S+(?:\s\S+)*) for owner name and (\S+(?:\s\S+)*) for group name — followed by a required numeric size field. When a crafted line has a valid Unix listing prefix but no valid size/date fields, the regex engine exhaustively tries every possible token split between the two groups before failing, resulting in O(n²) CPU cost relative to line length. Additionally, parseList() selects the parser based only on the last non-blank line, so an attacker can place a valid Unix-format line at the end of the listing to trigger the Unix parser, while an earlier crafted line causes the backtracking. The DOS-style parser in parseListDOS.ts was also found to have a similar unanchored regex and was patched simultaneously (GitHub Advisory, Fix Commit).
A malicious or compromised FTP server can send a single crafted directory listing that freezes the entire Node.js event loop for seconds to minutes — or longer — depending on the crafted line length. The PoC demonstrates that a 128 KB malicious line blocks the event loop for approximately 39 seconds, and since maxListingBytes defaults to 40 MB, a single line could block the process for tens of minutes. During this freeze, no other callbacks, timers, or requests are processed, resulting in complete denial of service of the application. There is no confidentiality or integrity impact; the vulnerability is limited to availability (GitHub Advisory).
A complete, runnable proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating event loop freezing with a crafted FTP server and client setup. The exploit is classified as automatable (NVD SSVC: automatable: yes) and requires no user interaction, though it does require the client to authenticate to the attacker-controlled server (credentials are supplied by the application). There is no evidence of in-the-wild exploitation at this time, and the EPSS score is 0.0. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Red Hat CVE).
USER, PASS, FEAT, EPSV, and LIST commands) using a framework such as Node.js net.createServer().-rw-r--r-- 1 ) followed by a large number of repeated a tokens (e.g., 128 KB worth) ending with ! (no valid size/date field), and a normal valid Unix-format line as the final line (e.g., -rw-r--r-- 1 owner group 42 Jan 1 2020 file.txt).Client.list().EPSV and LIST commands, the server responds with the crafted directory listing over the data connection.parseList() function selects the Unix parser based on the valid final line, then applies RE_LINE to every line including the malicious one. The regex engine backtracks across all possible owner/group token splits before failing, consuming O(n²) CPU time.LIST command responses (hundreds of KB to MB in a single line).list() call; application heartbeat/health check timeouts coinciding with FTP operations.Client.list() calls that do not return within expected timeframes; FTP session logs recording connections to untrusted or newly configured FTP server addresses; absence of timer/interval callbacks firing during an FTP listing operation.The primary remediation is to upgrade basic-ftp to version 6.2.1 or later, which anchors the RE_LINE regex and bounds the owner/group name quantifiers to a maximum of 8 words each ({0,7}), eliminating the quadratic backtracking (Fix Commit, Release v6.2.1). As a workaround for applications that cannot immediately upgrade, restrict FTP client connections to known, trusted FTP servers only, and implement network-level controls to prevent connections to arbitrary or attacker-controlled FTP endpoints. Organizations should audit all Node.js applications using basic-ftp <= 6.2.0 and prioritize patching for any that connect to externally controlled or potentially compromised FTP servers (GitHub Advisory).
The vulnerability was reported by security researcher NotAFlightRisk and disclosed via GitHub Security Advisory GHSA-c475-qrg2-pj4r on August 27, 2026. The advisory notes a similar prior vulnerability (GHSA-rp42-5vxx-qpwr) in the same Client.list() function, also rated High, suggesting a pattern of parser security issues in the library. Red Hat has tracked the issue as Deferred in their CVE database. No significant broader media coverage or social media discussion has been identified at this time (GitHub Advisory, Red Hat CVE).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."