CVE-2026-96780
### Impact A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when **both**: - `whitespaceBreak: true` is set, **and** - `width` is set smaller than the rendered width of a single FIGlet character. Under these conditions `breakWord()` could never find a valid break point, so the word-wrapping loop in `generateFigTextLines()` never terminated. This pins a CPU core and grows memory without bound, blocking the Node.js event loop. ### Severity Low or Medium. Triggering requires a non-default configuration (`whitespaceBreak: true`) and an attacker-controlled `width` value reaching `text()`/`textSync()`. This library is typically used with fixed options, where this is not reachable. Applications that pass an untrusted `width` together with `whitespaceBreak` on a request path are affected. ### Patches Fixed in **figlet 1.11.3**. `breakWord()` now always makes forward progress (emitting an over-wide character on its own line), and FIGlet header parsing now rejects invalid values (e.g. zero/negative height). ### Workarounds Do not expose `width` to untrusted input, or leave `whitespaceBreak` disabled (the default), or upgrade to 1.11.3.
Properties
- summary
- figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
- severity
- high
- epss_score
- 0.00405
- retrieved_at
- 2026-10-03T18:15:53+00:00
- ghsa_published
- 2026-10-02T22:39:16Z
- source_url
- https://github.com/advisories/GHSA-62ch-8vmq-8xm7
- ghsa_updated
- 2026-10-02T22:39:17Z
- ghsa_id
- GHSA-62ch-8vmq-8xm7
- last_source
- FIRST EPSS
- cve_id
- CVE-2026-96780
- signal_observed_at
- 2026-10-03T01:59:23+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.32495
Related Entities (5)
ENRICHED_BY (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph