{"id":"DEBIAN-CVE-2026-44240","details":"basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client keeps appending attacker-controlled data into FtpContext._partialResponse and repeatedly reparses the accumulated buffer without enforcing a maximum control response size. As a result, an application using basic-ftp can remain stuck in connect() while memory and CPU usage grow under attacker-controlled input. This can lead to process-level denial of service, container OOM kills, worker restarts, queue backlog, or service degradation in applications that automatically connect to FTP endpoints. This vulnerability is fixed in 5.3.1.","modified":"2026-08-27T23:06:01.426630465Z","published":"2026-05-12T21:16:16.410Z","upstream":["CVE-2026-44240"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-44240"}],"affected":[{"package":{"name":"node-proxy-agents","ecosystem":"Debian:13","purl":"pkg:deb/debian/node-proxy-agents?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0~2024040606-6","0~2024040606-6+deb13u1","0~2025070717+~cs15.2.7-1","0~2025070717+~cs15.3.7-1","0~2025070717+~cs15.3.8-1","0~2025070717+~cs15.3.8-2","0~2025070717+~cs15.3.8-3","0~2025070717-1","0~2025070717-2","0~2025070717-3","0~2025070717-4","0~2025070717-5","0~2025070717-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44240.json"}},{"package":{"name":"node-proxy-agents","ecosystem":"Debian:14","purl":"pkg:deb/debian/node-proxy-agents?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0~2025070717+~cs15.3.8-1"}]}],"versions":["0~2024040606-6","0~2025070717+~cs15.2.7-1","0~2025070717+~cs15.3.7-1","0~2025070717-1","0~2025070717-2","0~2025070717-3","0~2025070717-4","0~2025070717-5","0~2025070717-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44240.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}