OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-96780: figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width

GitHub Advisories · officialPublished Oct 2, 2026Risk 37/100

### Impact A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when **both**: - `whitespaceBreak: true` is set, **and** - `width` is set smaller than the rendered width of a single FIGlet character. Under these conditions `breakWord()` could never find a valid break point, so the word-wrapping loop in `generateFigTextLines()` never terminated. This pins a CPU core and grows memory without bound, blocking the Node.js event loop. ### Severity Low or Medium. Triggering requires a non-default configuration (`whitespaceBreak: true`) and an attacker-controlled `width` value reaching `text()`/`textSync()`. This library is typically used with fixed options, where this is not reachable. Applications that pass an untrusted `width` together with `whitespaceBreak` on a request path are affected. ### Patches Fixed in **figlet 1.11.3**. `breakWord()` now always makes forward progress (emitting an over-wide character on its own line), and FIGlet header parsing now rejects invalid values (e.g. zero/negative height). ### Workarounds Do not expose `width` to untrusted input, or leave `whitespaceBreak` disabled (the default), or upgrade to 1.11.3.

Upgrade affected packages to a patched version: figlet 1.11.3.

Vendor
Not specified
Product
figlet
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source