Skip to content
Threat Feed
medium advisory

ReDoS Vulnerability in basic-ftp Directory Listing Parser

A ReDoS vulnerability in the basic-ftp library allows a malicious FTP server to trigger quadratic-time CPU consumption during directory listing, causing a client-side denial of service.

CVE search metadata

CVE search record: CVE-2026-102990. EPSS: 0.51%. KEV: no. Product: basic-ftp (<= 6.2.0). Brief: ReDoS Vulnerability in basic-ftp Directory Listing Parser. Brief link: https://feed.craftedsignal.io/briefs/2026-10-basic-ftp-redos/

The basic-ftp Node.js library contains a high-severity regular expression denial of service (ReDoS) vulnerability, tracked as CVE-2026-102990. The vulnerability resides within the parseListUnix.js module, specifically in the RE_LINE regex used to parse Unix-style directory listings. The regex pattern utilizes two adjacent capture groups that are prone to excessive backtracking when provided with non-matching input strings that mimic a valid directory listing prefix but lack the subsequent mandatory numeric size and date fields.

An attacker controlling an FTP server can serve a crafted directory listing line to an basic-ftp client. When the client executes Client.list(), the regex engine attempts to resolve the ambiguous token structure, resulting in quadratic-time (O(n²)) CPU complexity relative to the length of the malicious string. Because Node.js is single-threaded, this operation blocks the event loop entirely, rendering the client unresponsive for extended periods. Given the default maxListingBytes of 40 MB, a single malicious line can effectively hang the client process for minutes.

Impact

The vulnerability results in a total client-side denial of service by freezing the Node.js event loop. This affects any application utilizing basic-ftp to connect to untrusted or compromised FTP servers. Depending on the scale of the malicious input provided, the process can remain unresponsive for extended periods, potentially disrupting mission-critical services or automated processes that rely on the FTP client.

Recommendation

Prioritized actions for teams using the basic-ftp library:

  • Update the basic-ftp package to a version patched against CVE-2026-102990.
  • Audit all code paths using Client.list() to ensure that connections are restricted to trusted FTP servers only.
  • Implement request timeouts at the application level to force-close connections that exceed expected latency thresholds, serving as a secondary mitigation against hanging event loops.

Mitigations

Upgrade basic-ftp to 6.2.1 or later

immediate Development

CVE-2026-102990