{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/basic-ftp--6.2.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:basic-ftp_project:basic-ftp:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"id":"CVE-2026-102990"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["basic-ftp (\u003c= 6.2.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe \u003ccode\u003ebasic-ftp\u003c/code\u003e Node.js library contains a high-severity regular expression denial of service (ReDoS) vulnerability, tracked as CVE-2026-102990. The vulnerability resides within the \u003ccode\u003eparseListUnix.js\u003c/code\u003e module, specifically in the \u003ccode\u003eRE_LINE\u003c/code\u003e regex used to parse Unix-style directory listings. The regex pattern utilizes two adjacent capture groups that are prone to excessive backtracking when provided with non-matching input strings that mimic a valid directory listing prefix but lack the subsequent mandatory numeric size and date fields.\u003c/p\u003e\n\u003cp\u003eAn attacker controlling an FTP server can serve a crafted directory listing line to an \u003ccode\u003ebasic-ftp\u003c/code\u003e client. When the client executes \u003ccode\u003eClient.list()\u003c/code\u003e, the regex engine attempts to resolve the ambiguous token structure, resulting in quadratic-time (O(n²)) CPU complexity relative to the length of the malicious string. Because Node.js is single-threaded, this operation blocks the event loop entirely, rendering the client unresponsive for extended periods. Given the default \u003ccode\u003emaxListingBytes\u003c/code\u003e of 40 MB, a single malicious line can effectively hang the client process for minutes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a total client-side denial of service by freezing the Node.js event loop. This affects any application utilizing \u003ccode\u003ebasic-ftp\u003c/code\u003e to connect to untrusted or compromised FTP servers. Depending on the scale of the malicious input provided, the process can remain unresponsive for extended periods, potentially disrupting mission-critical services or automated processes that rely on the FTP client.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for teams using the \u003ccode\u003ebasic-ftp\u003c/code\u003e library:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the \u003ccode\u003ebasic-ftp\u003c/code\u003e package to a version patched against CVE-2026-102990.\u003c/li\u003e\n\u003cli\u003eAudit all code paths using \u003ccode\u003eClient.list()\u003c/code\u003e to ensure that connections are restricted to trusted FTP servers only.\u003c/li\u003e\n\u003cli\u003eImplement request timeouts at the application level to force-close connections that exceed expected latency thresholds, serving as a secondary mitigation against hanging event loops.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T20:23:38Z","date_published":"2026-10-01T20:23:38Z","id":"https://feed.craftedsignal.io/briefs/2026-10-basic-ftp-redos/","summary":"A ReDoS vulnerability in the basic-ftp library allows a malicious FTP server to trigger quadratic-time CPU consumption during directory listing, causing a client-side denial of service.","title":"ReDoS Vulnerability in basic-ftp Directory Listing Parser","url":"https://feed.craftedsignal.io/briefs/2026-10-basic-ftp-redos/"}],"language":"en","title":"CraftedSignal Threat Feed - Basic-Ftp (\u003c= 6.2.0)","version":"https://jsonfeed.org/version/1.1"}