Quadratic CPU Time Vulnerability in basic-ftp FTP Client for Node.js
CVE-2026-102990

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102990?

The basic-ftp FTP client for Node.js has a vulnerability that allows a malicious FTP server to induce excessive CPU usage through the Client.list() function. An attacker can craft a directory listing that, due to the design flaw in the RE_LINE regex used for parsing, causes the application to consume quadratic CPU time. This occurs when valid prefix lines do not align with expected size and date fields, blocking the Node.js event loop and potentially freezing the entire process. The issue is addressed in version 6.2.1, underscoring the importance of keeping the client updated.

Affected Version(s)

basic-ftp < 6.2.1

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.