Allocation of Resources Without Limits or Throttling in basic-ftp - #VU128255
Published: April 28, 2026
basic-ftp
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in FtpContext._partialResponse and FTP control response parsing when processing unterminated multiline control-channel responses during the initial FTP banner phase. A remote attacker can send a specially crafted FTP server banner to cause a denial of service.
The issue is triggered before authentication, and no additional user interaction is required after the application initiates a normal FTP connection.