CVE-2026-96780

Source
https://cve.org/CVERecord?id=CVE-2026-96780
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96780.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-96780
Aliases
Published
2026-10-01T20:21:54Z
Modified
2026-10-03T03:47:00Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
Details

figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.11.3, text() and textSync() can enter an unbounded loop when whitespaceBreak is enabled and width is smaller than the rendered width of a single FIGlet character. Under these conditions, breakWord() cannot find a valid break point and returns without consuming a character, so generateFigTextLines() repeatedly processes the same input while consuming CPU and growing memory. The non-default option and attacker-controlled width must both reach an affected call. This issue is fixed in version 1.11.3.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-835"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96780.json"
}
References

Affected packages

Git / github.com/patorjk/figlet.js

Affected ranges

Type
GIT
Repo
https://github.com/patorjk/figlet.js
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.11.3"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.5.0
1.5.2
1.6.0
1.8.0
v1.*
v1.10.0
v1.11.0
v1.11.1
v1.11.2
v1.7.0
v1.8.0
v1.8.1
v1.8.2
v1.9.0
v1.9.1
v1.9.2
v1.9.3
v1.9.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96780.json"