CVE-2026-96780
Received Received - Intake

FIGlet.js Unbounded Loop in Text Rendering with Whitespace Break

Vulnerability report for CVE-2026-96780, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.11.3, text() and textSync() can enter an unbounded loop when whitespaceBreak is enabled and width is smaller than the rendered width of a single FIGlet character. Under these conditions, breakWord() cannot find a valid break point and returns without consuming a character, so generateFigTextLines() repeatedly processes the same input while consuming CPU and growing memory. The non-default option and attacker-controlled width must both reach an affected call. This issue is fixed in version 1.11.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

figlet.js is a JavaScript library for rendering text in FIGlet fonts. A flaw exists in versions before 1.11.3 where the text() and textSync() functions can enter an infinite loop if whitespaceBreak is enabled and the specified width is smaller than a single character's rendered width. This causes the system to repeatedly process the same input without progress, consuming excessive CPU and memory.

Detection Guidance

This vulnerability can be detected by checking if figlet.js version 1.11.3 or later is installed. Run 'npm list figlet' or 'npm list -g figlet' to check the installed version. If the version is below 1.11.3, the system is vulnerable.

Impact Analysis

This vulnerability can cause denial-of-service by consuming all available CPU and memory resources on the system running the affected application. It requires both the non-default whitespaceBreak option and an attacker-controlled width parameter to be exploited.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a denial-of-service issue in figlet.js causing CPU and memory exhaustion under specific conditions, but does not involve data breaches or unauthorized access.

Mitigation Strategies

Immediately update figlet.js to version 1.11.3 or later using 'npm update figlet' or 'npm install figlet@latest'. If updating is not possible, disable the whitespaceBreak option in figlet.js configurations to prevent the unbounded loop.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96780. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart