GHSA-62ch-8vmq-8xm7

Suggest an improvement
Source
https://github.com/advisories/GHSA-62ch-8vmq-8xm7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-62ch-8vmq-8xm7/GHSA-62ch-8vmq-8xm7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-62ch-8vmq-8xm7
Aliases
Published
2026-10-02T22:39:16Z
Modified
2026-10-02T23:01:22Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
Details

Impact

A denial-of-service (infinite loop) can occur in text() / textSync() when both:

  • whitespaceBreak: true is set, and
  • width is set smaller than the rendered width of a single FIGlet character. Under these conditions breakWord() could never find a valid break point, so the word-wrapping loop in generateFigTextLines() never terminated. This pins a CPU core and grows memory without bound, blocking the Node.js event loop.

Severity

Low or Medium. Triggering requires a non-default configuration (whitespaceBreak: true) and an attacker-controlled width value reaching text()/textSync(). This library is typically used with fixed options, where this is not reachable. Applications that pass an untrusted width together with whitespaceBreak on a request path are affected.

Patches

Fixed in figlet 1.11.3. breakWord() now always makes forward progress (emitting an over-wide character on its own line), and FIGlet header parsing now rejects invalid values (e.g. zero/negative height).

Workarounds

Do not expose width to untrusted input, or leave whitespaceBreak disabled (the default), or upgrade to 1.11.3.

Database specific
{
    "cwe_ids":  [
        "CWE-835"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-02T22:39:16Z",
    "nvd_published_at":  "2026-10-01T21:17:26Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / figlet

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.11.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-62ch-8vmq-8xm7/GHSA-62ch-8vmq-8xm7.json"