Unbounded Loop Vulnerability in figlet.js from Patorjk
CVE-2026-96780

8.2HIGH

Key Information:

Vendor

Patorjk

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-96780?

The figlet.js library, which implements the FIGfont specification, is susceptible to an unbounded loop issue in its text handling functions prior to version 1.11.3. When the 'whitespaceBreak' option is enabled and the specified width is narrower than the rendered width of a FIGlet character, the functions text() and textSync() can enter an infinite loop. This leads to excessive CPU utilization and memory consumption as the generateFigTextLines() function continuously processes the same input without consuming a character. The vulnerability is triggered under specific conditions involving the non-default option and manipulated width values, making it critical for users to update to version 1.11.3 or later to mitigate this risk.

Affected Version(s)

figlet.js < 1.11.3

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.