Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.3 Node.js & npm GHSA-62ch-8vmq-8xm7 CVE-2026-96780

figlet.js Denial-of-Service Vulnerability Fixed in Version 1.11.3 (CVE-2026-96780)

A denial-of-service vulnerability in figlet.js, triggered by an unbounded loop under specific non-default configuration, has been fixed in version 1.11.3. Applications that enable the whitespaceBreak option and allow attacker-controlled width values are affected.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A vulnerability has been identified in figlet.js, a JavaScript library that renders text using FIGlet fonts. The issue can cause the library to enter an unbounded loop under certain configurations, leading to denial of service. A fix is available in version 1.11.3.

What happened

A vulnerability (CVE-2026-96780, GHSA-62ch-8vmq-8xm7) was identified in figlet.js, a FIG driver written in JavaScript that implements the FIGlet font specification. The text() and textSync() functions can enter an unbounded loop under specific conditions, causing excessive CPU consumption and memory growth.

Technical cause

The issue occurs when the whitespaceBreak option is enabled and the configured width is smaller than the rendered width of a single FIGlet character. Under these conditions, the internal breakWord() function cannot find a valid break point and returns without consuming a character. As a result, generateFigTextLines() repeatedly processes the same input in a loop that never terminates, consuming CPU and growing memory usage. This is classified as CWE-835, Loop with Unreachable Exit Condition ('Infinite Loop').

Why it matters

Triggering this vulnerability requires both the non-default whitespaceBreak option to be enabled and an attacker-controlled width value to reach an affected call. Where these conditions are met, an application could be made unresponsive or consume excessive resources without requiring authentication or user interaction, which can lead to denial of service for the affected service.

Who is affected

Applications using the figlet npm package that enable the whitespaceBreak option and allow width values derived from attacker-controlled input are affected. Applications that do not use whitespaceBreak, or that do not expose width to untrusted input, are not affected by this specific trigger path.

Affected versions

All versions of figlet prior to 1.11.3 are affected. The issue is fixed in version 1.11.3.

Fixes and mitigation

The vendor has released version 1.11.3 of figlet, which fixes this issue. Users of the figlet npm package should update to version 1.11.3 or later.

Recommended action

Update the figlet package to version 1.11.3 or later. If immediate upgrading is not possible, review whether whitespaceBreak is enabled in your configuration and whether the width parameter can be influenced by untrusted input, and restrict or validate that input as an interim mitigation.

PatchBriefing score

5.3 / 10 · Medium

Official CVSS: 8.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

The PatchBriefing score of 5.3 reflects a CVSS 4.0 base score of 8.2, driven primarily by the high availability impact of the unbounded loop. The score includes additional weight for the fact that the vulnerability can be triggered without authentication and without user interaction. However, there is no known exploitation in the wild, no public exploit code, and no EPSS probability data available, and the trigger requires a non-default configuration (whitespaceBreak enabled) combined with attacker control over the width parameter, which limits the real-world attack surface compared to a fully default-exploitable issue. A fix is available, which also moderates the overall urgency.

Affected versions

figlet < 1.11.3
vulnerable
≥ 1.11.3
patched

Reported fixes

The vendor has released version 1.11.3 of figlet, which fixes this issue. Users of the figlet npm package should update to version 1.11.3 or later.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
figlet.js Denial-of-Service Vulnerability Fixed in Version 1.11.3 (CVE-2026-96780)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email