OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102990

HIGH · CVSS 8.2 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The basic-ftp client for Node.js versions prior to 6.2.1 is vulnerable to a denial-of-service attack, where a malicious FTP server can exploit the Client.list() method to cause excessive CPU consumption through inefficient parsing of directory listings. This vulnerability can lead to the Node.js event loop being blocked, effectively freezing the application. Organizations using basic-ftp in their Node.js applications should prioritize upgrading to version 6.2.1 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102990
Severity
HIGH
CVSS
8.2
EPSS
0.37%

Original NVD Description

basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.