#VU126358 Allocation of Resources Without Limits or Throttling in basic-ftp
Published: April 16, 2026
basic-ftp
patrickjuchli
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in Client.list() and StringWriter when processing directory listings from a remote FTP server. A remote attacker can send an extremely large or never-ending listing response to cause a denial of service.
Exploitation requires the victim to connect to a malicious or compromised FTP server and perform a directory listing operation.