Denial of Service Vulnerability in basic-ftp by patrickjuchli
CVE-2026-41324

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
24 April 2026

What is CVE-2026-41324?

The basic-ftp client for Node.js is susceptible to a denial of service vulnerability due to unbounded memory growth when processing directory listings from compromised FTP servers. Attackers can exploit this flaw by sending excessively large or endless directory responses during the Client.list() operation, leading to memory exhaustion that may cause the application to crash or become unstable. The issue has been rectified in version 5.3.0.

Affected Version(s)

basic-ftp < 5.3.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.