Source: node-proxy-agents Version: 0~2025070717+~cs15.3.8-3 X-Debbugs-CC: [email protected] Severity: important Tags: security upstream
Hi, The following vulnerability was published for node-proxy-agents. CVE-2026-102990[0]: | basic-ftp is an FTP client for Node.js. Prior to 6.2.1, | Client.list() can be forced by a malicious or compromised FTP server | to spend quadratic CPU time parsing a directory listing because the | RE_LINE expression in src/parseListUnix.ts backtracks across | adjacent variable-length owner and group fields when a long Unix- | style line has a valid prefix but cannot satisfy the later size and | date fields. parseList() selects a parser from the last nonblank | line and then applies it to every line, so a normal final line can | select the Unix parser while an earlier crafted line blocks the | Node.js event loop and freezes the process. This issue is fixed in | version 6.2.1. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-102990 https://www.cve.org/CVERecord?id=CVE-2026-102990 [1] https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r [2] https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9 Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- Pkg-javascript-devel mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel
