<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Basic-Ftp (&lt;= 6.2.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/basic-ftp--6.2.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:23:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/basic-ftp--6.2.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>ReDoS Vulnerability in basic-ftp Directory Listing Parser</title><link>https://feed.craftedsignal.io/briefs/2026-10-basic-ftp-redos/</link><pubDate>Thu, 01 Oct 2026 20:23:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-basic-ftp-redos/</guid><description>A ReDoS vulnerability in the basic-ftp library allows a malicious FTP server to trigger quadratic-time CPU consumption during directory listing, causing a client-side denial of service.</description><content:encoded><![CDATA[<p>The <code>basic-ftp</code> Node.js library contains a high-severity regular expression denial of service (ReDoS) vulnerability, tracked as CVE-2026-102990. The vulnerability resides within the <code>parseListUnix.js</code> module, specifically in the <code>RE_LINE</code> regex used to parse Unix-style directory listings. The regex pattern utilizes two adjacent capture groups that are prone to excessive backtracking when provided with non-matching input strings that mimic a valid directory listing prefix but lack the subsequent mandatory numeric size and date fields.</p>
<p>An attacker controlling an FTP server can serve a crafted directory listing line to an <code>basic-ftp</code> client. When the client executes <code>Client.list()</code>, the regex engine attempts to resolve the ambiguous token structure, resulting in quadratic-time (O(n²)) CPU complexity relative to the length of the malicious string. Because Node.js is single-threaded, this operation blocks the event loop entirely, rendering the client unresponsive for extended periods. Given the default <code>maxListingBytes</code> of 40 MB, a single malicious line can effectively hang the client process for minutes.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in a total client-side denial of service by freezing the Node.js event loop. This affects any application utilizing <code>basic-ftp</code> to connect to untrusted or compromised FTP servers. Depending on the scale of the malicious input provided, the process can remain unresponsive for extended periods, potentially disrupting mission-critical services or automated processes that rely on the FTP client.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for teams using the <code>basic-ftp</code> library:</p>
<ul>
<li>Update the <code>basic-ftp</code> package to a version patched against CVE-2026-102990.</li>
<li>Audit all code paths using <code>Client.list()</code> to ensure that connections are restricted to trusted FTP servers only.</li>
<li>Implement request timeouts at the application level to force-close connections that exceed expected latency thresholds, serving as a secondary mitigation against hanging event loops.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>