Allocation of Resources Without Limits or Throttling in basic-ftp - CVE-2026-44240
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in FtpContext._partialResponse and FTP control response parsing when processing unterminated multiline control-channel responses during the initial FTP banner phase. A remote attacker can send a specially crafted FTP server banner to cause a denial of service.
The issue is triggered before authentication, and no additional user interaction is required after the application initiates a normal FTP connection.