CVE-2026-102990: CVE-2026-102990: Regular Expression Denial of Service in basic-ftp Directory Parsing
CVE-2026-102990: Regular Expression Denial of Service in basic-ftp Directory Parsing Vulnerability ID: CVE-2026-102990 CVSS Score: 8.2 Published: 2026-10-01 A highly critical Regular Expression Denial of Service (Re
CVE-2026-102990: Regular Expression Denial of Service in basic-ftp Directory Parsing
Vulnerability ID: CVE-2026-102990
CVSS Score: 8.2
Published: 2026-10-01
A highly critical Regular Expression Denial of Service (ReDoS) vulnerability in basic-ftp, an FTP client library for Node.js. In versions prior to 6.2.1, a malicious or compromised FTP server can exploit this vulnerability to force the FTP client to consume quadratic CPU time during directory parsing. This issue blocks the single-threaded Node.js event loop, freezing the application process and leading to a complete Denial of Service (DoS).
TL;DR
Unanchored regular expressions and adjacent variable-length capture groups in basic-ftp's Unix and DOS directory-listing parsers allow a malicious FTP server to cause CPU exhaustion and freeze Node.js client applications.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-1333
- Attack Vector: Network
- CVSS v4.0: 8.2 (High)
- EPSS Score: 0.00507
- Impact: Availability (High)
- Exploit Status: PoC Available
- KEV Status: Not Listed
Affected Systems
- basic-ftp NPM package versions prior to 6.2.1
- Node.js applications consuming basic-ftp for directory listing processing
-
basic-ftp: < 6.2.1 (Fixed in:
6.2.1)
Code Analysis
Commit: d0d9e07
Fix ReDoS vulnerabilities in Unix and DOS directory listing parsers
Exploit Details
- GitHub (Official regression test suite): Regression test cases demonstrating ReDoS using crafted directories
Mitigation Strategies
- Upgrade basic-ftp to version 6.2.1 or newer.
- Avoid connecting to untrusted or user-supplied FTP server addresses.
- Use network egress filtering to restrict FTP connections to trusted hosts.
- Run directory listing operations inside isolated worker threads or child processes.
Remediation Steps:
- Run 'npm install [email protected]' to update the dependency to a secure version.
- Audit the dependency tree using 'npm list basic-ftp' to identify vulnerable transitive dependencies.
- Verify the update using the official regression test suite to ensure DoS resistance is active.
References
Read the full report for CVE-2026-102990 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.