CVE-2026-44240Patch

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client keeps appending attacker-controlled data into FtpContext._partialResponse and repeatedly reparses the accumulated buffer without enforcing a maximum control response size. As a result, an application using basic-ftp can remain stuck in connect() while memory and CPU usage grow under attacker-controlled input. This can lead to process-level denial of service, container OOM kills, worker restarts, queue backlog, or service degradation in applications that automatically connect to FTP endpoints. This vulnerability is fixed in 5.3.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-06); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-06: 1Mentions · 2026-05-12: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-12: 105-0605-12
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-061
Patch1
2026-05-121
General1
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 basic-ftp DoS Vulnerability: CVE-2026-44240 A high-severity denial-of-service flaw in basic-ftp could let malicious FTP servers exhaust memory by sending endless multiline responses. Affected: basic-ftp 0.0.1–5.3.0 Fixed in: 5.3.1 #NodeJS #npm #OpenSource #CyberSecurity

    Post summary

    CVE‑2026‑44240 is a high‑severity DoS flaw in basic‑ftp that has been fixed in version 5.3.1, and the note provides the patch release information.

    0001082
    149 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-44240 basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses.… https://www.cve.org/CVERecord?id=CVE-2026-44240

    Post summary

    The content reports a client‑side denial‑of‑service issue in basic‑ftp (Node.js) prior to version 5.3.1, noting the vulnerability type and affected parsing logic, but it offers no proof of concept, exploit, patch, or evidence of active exploitation.

    0000087
    57.5K followersView on X

Explore more