← Back to CVE List
CVE-2026-96780NVD
Vulnerability Summary
### Impact
A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when
**both**:
- `whitespaceBreak: true` is set, **and**
- `width` is set smaller than the rendered width of a single FIGlet character.
Under these conditions `breakWord()` could never find a valid break point, so the
word-wrapping loop in `generateFigTextLines()` never terminated. This pins a CPU
core and grows memory without bound, blocking the Node.js event loop.
### Severity
Low or Medium. Triggering requires a non-default configuration (`whitespaceBreak: true`) and
an attacker-controlled `width` value reaching `text()`/`textSync()`. This library is typically
used with fixed options, where this is not
reachable. Applications that pass an untrusted `width` together with
`whitespaceBreak` on a request path are affected.
### Patches
Fixed in **figlet 1.11.3**. `breakWord()` now always makes forward progress
(emitting an over-wide character on its own line), and FIGlet header parsing now
rejects invalid values (e.g. zero/negative height).
### Workarounds
Do not expose `width` to untrusted input, or leave `whitespaceBreak` disabled
(the default), or upgrade to 1.11.3.
A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when
**both**:
- `whitespaceBreak: true` is set, **and**
- `width` is set smaller than the rendered width of a single FIGlet character.
Under these conditions `breakWord()` could never find a valid break point, so the
word-wrapping loop in `generateFigTextLines()` never terminated. This pins a CPU
core and grows memory without bound, blocking the Node.js event loop.
### Severity
Low or Medium. Triggering requires a non-default configuration (`whitespaceBreak: true`) and
an attacker-controlled `width` value reaching `text()`/`textSync()`. This library is typically
used with fixed options, where this is not
reachable. Applications that pass an untrusted `width` together with
`whitespaceBreak` on a request path are affected.
### Patches
Fixed in **figlet 1.11.3**. `breakWord()` now always makes forward progress
(emitting an over-wide character on its own line), and FIGlet header parsing now
rejects invalid values (e.g. zero/negative height).
### Workarounds
Do not expose `width` to untrusted input, or leave `whitespaceBreak` disabled
(the default), or upgrade to 1.11.3.
CVSS v4.0 Base Metrics — Score 8.2
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- figlet < 1.11.3
Not provided by Private for this CVE.
External References
- https://github.com/patorjk/figlet.js/security/advisories/GHSA-62ch-8vmq-8xm7
- https://nvd.nist.gov/vuln/detail/CVE-2026-96780
- https://github.com/patorjk/figlet.js/pull/169
- https://github.com/patorjk/figlet.js/commit/cb2839d0e53aeafbd361e9587abc72e49e41cbb3
- https://github.com/advisories/GHSA-62ch-8vmq-8xm7