Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-102990: CVE-2026-102990: Regular Expression Denial of Service in basic-ftp Directory Parsing

CVE-2026-102990: Regular Expression Denial of Service in basic-ftp Directory Parsing Vulnerability ID: CVE-2026-102990 CVSS Score: 8.2 Published: 2026-10-01 A highly critical Regular Expression Denial of Service (Re

CVE-2026-102990: Regular Expression Denial of Service in basic-ftp Directory Parsing

Vulnerability ID: CVE-2026-102990
CVSS Score: 8.2
Published: 2026-10-01

A highly critical Regular Expression Denial of Service (ReDoS) vulnerability in basic-ftp, an FTP client library for Node.js. In versions prior to 6.2.1, a malicious or compromised FTP server can exploit this vulnerability to force the FTP client to consume quadratic CPU time during directory parsing. This issue blocks the single-threaded Node.js event loop, freezing the application process and leading to a complete Denial of Service (DoS).

TL;DR

Unanchored regular expressions and adjacent variable-length capture groups in basic-ftp's Unix and DOS directory-listing parsers allow a malicious FTP server to cause CPU exhaustion and freeze Node.js client applications.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-1333
  • Attack Vector: Network
  • CVSS v4.0: 8.2 (High)
  • EPSS Score: 0.00507
  • Impact: Availability (High)
  • Exploit Status: PoC Available
  • KEV Status: Not Listed

Affected Systems

  • basic-ftp NPM package versions prior to 6.2.1
  • Node.js applications consuming basic-ftp for directory listing processing
  • basic-ftp: < 6.2.1 (Fixed in: 6.2.1)

Code Analysis

Commit: d0d9e07

Fix ReDoS vulnerabilities in Unix and DOS directory listing parsers

Exploit Details

Mitigation Strategies

  • Upgrade basic-ftp to version 6.2.1 or newer.
  • Avoid connecting to untrusted or user-supplied FTP server addresses.
  • Use network egress filtering to restrict FTP connections to trusted hosts.
  • Run directory listing operations inside isolated worker threads or child processes.

Remediation Steps:

  1. Run 'npm install [email protected]' to update the dependency to a secure version.
  2. Audit the dependency tree using 'npm list basic-ftp' to identify vulnerable transitive dependencies.
  3. Verify the update using the official regression test suite to ensure DoS resistance is active.

References

Read the full report for CVE-2026-102990 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.