Source: node-proxy-agents
Version: 0~2025070717+~cs15.3.8-3
X-Debbugs-CC: [email protected]
Severity: important
Tags: security upstream

Hi,

The following vulnerability was published for node-proxy-agents.

CVE-2026-102990[0]:
| basic-ftp is an FTP client for Node.js. Prior to 6.2.1,
| Client.list() can be forced by a malicious or compromised FTP server
| to spend quadratic CPU time parsing a directory listing because the
| RE_LINE expression in src/parseListUnix.ts backtracks across
| adjacent variable-length owner and group fields when a long Unix-
| style line has a valid prefix but cannot satisfy the later size and
| date fields. parseList() selects a parser from the last nonblank
| line and then applies it to every line, so a normal final line can
| select the Unix parser while an earlier crafted line blocks the
| Node.js event loop and freezes the process. This issue is fixed in
| version 6.2.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102990
    https://www.cve.org/CVERecord?id=CVE-2026-102990
[1] 
https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r
[2] 
https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to