SB2026041650 - Allocation of Resources Without Limits or Throttling in basic-ftp
Published: April 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in Client.list() and StringWriter when processing directory listings from a remote FTP server. A remote attacker can send an extremely large or never-ending listing response to cause a denial of service.
Exploitation requires the victim to connect to a malicious or compromised FTP server and perform a directory listing operation.
Remediation
Install update from vendor's website.