PT-2026-104016 · Npm · Figlet.Js

CVE-2026-96780

·

Published

2026-10-01

·

Updated

2026-10-02

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions figlet.js versions prior to 1.11.3
Description An unbounded loop can occur within the text() and textSync() functions when the whitespaceBreak option is enabled and the width variable is set to a value smaller than the rendered width of a single FIGlet character. In this scenario, the breakWord() function fails to find a valid break point and returns without consuming a character, causing the generateFigTextLines() function to repeatedly process the same input. This leads to excessive CPU consumption and memory growth.
Recommendations Update to version 1.11.3.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96780

Affected Products

Figlet.Js