{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afiglet_projectfigletnode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:figlet_project:figlet:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"id":"CVE-2026-96780"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["figlet (\u003c 1.11.3)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe figlet Node.js library (versions prior to 1.11.3) is susceptible to a denial-of-service vulnerability triggered by an unbounded loop in the \u003ccode\u003ebreakWord()\u003c/code\u003e function. The flaw occurs when an application calls \u003ccode\u003etext()\u003c/code\u003e or \u003ccode\u003etextSync()\u003c/code\u003e with the configuration \u003ccode\u003ewhitespaceBreak: true\u003c/code\u003e and a \u003ccode\u003ewidth\u003c/code\u003e setting smaller than the width of a single character in the FIGlet font. Under these specific conditions, the word-wrapping logic in \u003ccode\u003egenerateFigTextLines()\u003c/code\u003e fails to identify a valid break point, causing the process to enter an infinite loop. This behavior pins a single CPU core at 100% usage and results in unbounded memory growth, effectively blocking the Node.js event loop and rendering the service unresponsive. The issue is resolved in version 1.11.3 by updating the word-wrapping logic to guarantee forward progress and implementing validation to reject invalid header values like zero or negative widths.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial-of-service condition for the target Node.js application. This vulnerability is most dangerous in web applications that reflect user-supplied input into the \u003ccode\u003ewidth\u003c/code\u003e parameter of the figlet function. Continuous exploitation can lead to prolonged service outages, impacting availability for all users. The severity is mitigated by the fact that the exploit requires both non-default configuration (\u003ccode\u003ewhitespaceBreak: true\u003c/code\u003e) and access to the function's parameters via untrusted input.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to mitigate this vulnerability:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the figlet dependency to version 1.11.3 or later in all projects.\u003c/li\u003e\n\u003cli\u003eAudit applications utilizing figlet to determine if the \u003ccode\u003ewidth\u003c/code\u003e parameter is influenced by untrusted user input.\u003c/li\u003e\n\u003cli\u003eDisable the \u003ccode\u003ewhitespaceBreak\u003c/code\u003e option if it is not strictly required for business logic, as it remains the primary driver for this vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T22:50:20Z","date_published":"2026-10-02T22:50:20Z","id":"https://feed.craftedsignal.io/briefs/2026-10-figlet-dos/","summary":"An infinite loop vulnerability in the figlet Node.js library, tracked as CVE-2026-96780, allows unauthenticated attackers to exhaust CPU and memory resources if they can influence the 'width' parameter in applications using 'whitespaceBreak: true'.","title":"Denial of Service in figlet Node.js Library","url":"https://feed.craftedsignal.io/briefs/2026-10-figlet-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:figlet_project:figlet:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}