Medium · 5.3 Node.js & npm GHSA-62ch-8vmq-8xm7 CVE-2026-96780
figlet.js Denial-of-Service Vulnerability Fixed in Version 1.11.3 (CVE-2026-96780)
A denial-of-service vulnerability in figlet.js, triggered by an unbounded loop under specific non-default configuration, has been fixed in version 1.11.3. Applications that enable the whitespaceBreak option and allow attacker-controlled width values are affected.
AI summary
A vulnerability has been identified in figlet.js, a JavaScript library that renders text using FIGlet fonts. The issue can cause the library to enter an unbounded loop under certain configurations, leading to denial of service. A fix is available in version 1.11.3.
What happened
A vulnerability (CVE-2026-96780, GHSA-62ch-8vmq-8xm7) was identified in figlet.js, a FIG driver written in JavaScript that implements the FIGlet font specification. The text() and textSync() functions can enter an unbounded loop under specific conditions, causing excessive CPU consumption and memory growth.
Technical cause
The issue occurs when the whitespaceBreak option is enabled and the configured width is smaller than the rendered width of a single FIGlet character. Under these conditions, the internal breakWord() function cannot find a valid break point and returns without consuming a character. As a result, generateFigTextLines() repeatedly processes the same input in a loop that never terminates, consuming CPU and growing memory usage. This is classified as CWE-835, Loop with Unreachable Exit Condition ('Infinite Loop').
Why it matters
Triggering this vulnerability requires both the non-default whitespaceBreak option to be enabled and an attacker-controlled width value to reach an affected call. Where these conditions are met, an application could be made unresponsive or consume excessive resources without requiring authentication or user interaction, which can lead to denial of service for the affected service.
Who is affected
Applications using the figlet npm package that enable the whitespaceBreak option and allow width values derived from attacker-controlled input are affected. Applications that do not use whitespaceBreak, or that do not expose width to untrusted input, are not affected by this specific trigger path.
Affected versions
All versions of figlet prior to 1.11.3 are affected. The issue is fixed in version 1.11.3.
Fixes and mitigation
The vendor has released version 1.11.3 of figlet, which fixes this issue. Users of the figlet npm package should update to version 1.11.3 or later.
Recommended action
Update the figlet package to version 1.11.3 or later. If immediate upgrading is not possible, review whether whitespaceBreak is enabled in your configuration and whether the width parameter can be influenced by untrusted input, and restrict or validate that input as an interim mitigation.
PatchBriefing score
5.3 / 10 · Medium
Official CVSS: 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
The PatchBriefing score of 5.3 reflects a CVSS 4.0 base score of 8.2, driven primarily by the high availability impact of the unbounded loop. The score includes additional weight for the fact that the vulnerability can be triggered without authentication and without user interaction. However, there is no known exploitation in the wild, no public exploit code, and no EPSS probability data available, and the trigger requires a non-default configuration (whitespaceBreak enabled) combined with attacker control over the width parameter, which limits the real-world attack surface compared to a fully default-exploitable issue. A fix is available, which also moderates the overall urgency.
Affected versions
- figlet < 1.11.3
- vulnerable
- ≥ 1.11.3
- patched
Reported fixes
The vendor has released version 1.11.3 of figlet, which fixes this issue. Users of the figlet npm package should update to version 1.11.3 or later.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email