highVulnerability

CVE-2026-96780

### Impact A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when **both**: - `whitespaceBreak: true` is set, **and** - `width` is set smaller than the rendered width of a single FIGlet character. Under these conditions `breakWord()` could never find a valid break point, so the word-wrapping loop in `generateFigTextLines()` never terminated. This pins a CPU core and grows memory without bound, blocking the Node.js event loop. ### Severity Low or Medium. Triggering requires a non-default configuration (`whitespaceBreak: true`) and an attacker-controlled `width` value reaching `text()`/`textSync()`. This library is typically used with fixed options, where this is not reachable. Applications that pass an untrusted `width` together with `whitespaceBreak` on a request path are affected. ### Patches Fixed in **figlet 1.11.3**. `breakWord()` now always makes forward progress (emitting an over-wide character on its own line), and FIGlet header parsing now rejects invalid values (e.g. zero/negative height). ### Workarounds Do not expose `width` to untrusted input, or leave `whitespaceBreak` disabled (the default), or upgrade to 1.11.3.

Properties

summary
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
severity
high
epss_score
0.00405
retrieved_at
2026-10-03T18:15:53+00:00
ghsa_published
2026-10-02T22:39:16Z
source_url
https://github.com/advisories/GHSA-62ch-8vmq-8xm7
ghsa_updated
2026-10-02T22:39:17Z
ghsa_id
GHSA-62ch-8vmq-8xm7
last_source
FIRST EPSS
cve_id
CVE-2026-96780
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
false
epss_percentile
0.32495

Related Entities (5)

ENRICHED_BY (1)

→[Source]FIRST EPSS

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/figlet

AFFECTS (1)

→[Software]npm/figlet

HAS_WEAKNESS (1)

→[Weakness]Loop with Unreachable Exit Condition ('Infinite Loop')

Explore deeper with Ninja Signal's threat intelligence graph