{"id":"DEBIAN-CVE-2026-102990","details":"basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.","modified":"2026-10-01T12:00:07.007343517Z","published":"2026-09-30T20:17:26.140Z","upstream":["CVE-2026-102990"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-102990"}],"affected":[{"package":{"name":"node-proxy-agents","ecosystem":"Debian:13","purl":"pkg:deb/debian/node-proxy-agents?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0~2024040606-6","0~2024040606-6+deb13u1","0~2025070717+~cs15.2.7-1","0~2025070717+~cs15.3.7-1","0~2025070717+~cs15.3.8-1","0~2025070717+~cs15.3.8-2","0~2025070717+~cs15.3.8-3","0~2025070717-1","0~2025070717-2","0~2025070717-3","0~2025070717-4","0~2025070717-5","0~2025070717-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102990.json"}},{"package":{"name":"node-proxy-agents","ecosystem":"Debian:14","purl":"pkg:deb/debian/node-proxy-agents?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0~2024040606-6","0~2025070717+~cs15.2.7-1","0~2025070717+~cs15.3.7-1","0~2025070717+~cs15.3.8-1","0~2025070717+~cs15.3.8-2","0~2025070717+~cs15.3.8-3","0~2025070717-1","0~2025070717-2","0~2025070717-3","0~2025070717-4","0~2025070717-5","0~2025070717-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102990.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}