basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
Published Sep 30, 2026
8.2
HIGHCVSS 4.0
EPSS 0.51%
Description
basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.
Affected products
-
- Version < 6.2.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Patrickjuchli | Basic-Ftp | n/a |
|
No data.
No data.
Red Hat Developer Hub
rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend
Affected
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Affected
Red Hat Enterprise Linux 10
grafana
Affected
Red Hat Enterprise Linux 10
rust
Not affected
Red Hat Enterprise Linux 8
rust-toolset:rhel8/rust
Not affected
Red Hat Enterprise Linux 9
rust
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rust
Affected
Red Hat Hardened Images
grafana12.4
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
Affected
Red Hat OpenShift GitOps
microshift-gitops
Affected
Red Hat OpenShift GitOps
openshift-gitops-argocd-cli
Affected
Self-service automation portal 2
ansible-automation-platform/automation-portal
Affected
Self-service automation portal 2
ansible-automation-platform/bootc-automation-portal-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Hub | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend | Affected | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux 10 | grafana | Affected | n/a |
| Red Hat Enterprise Linux 10 | rust | Not affected | n/a |
| Red Hat Enterprise Linux 8 | rust-toolset:rhel8/rust | Not affected | n/a |
| Red Hat Enterprise Linux 9 | rust | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rust | Affected | n/a |
| Red Hat Hardened Images | grafana12.4 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 | Affected | n/a |
| Red Hat OpenShift GitOps | microshift-gitops | Affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-argocd-cli | Affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/automation-portal | Affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Affected | n/a |
basic-ftp
npm
Introduced 0 Fixed 6.2.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | basic-ftp | 0 | 6.2.1 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Sep 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-102990 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2544216 Issue Tracking
- https://github.com/advisories/GHSA-c475-qrg2-pj4r Advisory
- https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9 x_refsource_MISC
- https://github.com/patrickjuchli/basic-ftp/releases/tag/v6.2.1 x_refsource_MISC
- https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-102990
- https://www.cve.org/CVERecord?id=CVE-2026-102990
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-102990 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2544216 | Issue Tracking | |
| https://github.com/advisories/GHSA-c475-qrg2-pj4r | Advisory | |
| https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9 | x_refsource_MISC | |
| https://github.com/patrickjuchli/basic-ftp/releases/tag/v6.2.1 | x_refsource_MISC | |
| https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-102990 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-102990 |
Change history (0)
No recorded changes yet.