PT-2026-104016 · Npm · Figlet.Js
CVE-2026-96780
·
Published
2026-10-01
·
Updated
2026-10-02
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
figlet.js versions prior to 1.11.3
Description
An unbounded loop can occur within the
text() and textSync() functions when the whitespaceBreak option is enabled and the width variable is set to a value smaller than the rendered width of a single FIGlet character. In this scenario, the breakWord() function fails to find a valid break point and returns without consuming a character, causing the generateFigTextLines() function to repeatedly process the same input. This leads to excessive CPU consumption and memory growth.Recommendations
Update to version 1.11.3.
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Figlet.Js