<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Figlet (&lt; 1.11.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/figlet--1.11.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 22:50:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/figlet--1.11.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service in figlet Node.js Library</title><link>https://feed.craftedsignal.io/briefs/2026-10-figlet-dos/</link><pubDate>Fri, 02 Oct 2026 22:50:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-figlet-dos/</guid><description>An infinite loop vulnerability in the figlet Node.js library, tracked as CVE-2026-96780, allows unauthenticated attackers to exhaust CPU and memory resources if they can influence the 'width' parameter in applications using 'whitespaceBreak: true'.</description><content:encoded><![CDATA[<p>The figlet Node.js library (versions prior to 1.11.3) is susceptible to a denial-of-service vulnerability triggered by an unbounded loop in the <code>breakWord()</code> function. The flaw occurs when an application calls <code>text()</code> or <code>textSync()</code> with the configuration <code>whitespaceBreak: true</code> and a <code>width</code> setting smaller than the width of a single character in the FIGlet font. Under these specific conditions, the word-wrapping logic in <code>generateFigTextLines()</code> fails to identify a valid break point, causing the process to enter an infinite loop. This behavior pins a single CPU core at 100% usage and results in unbounded memory growth, effectively blocking the Node.js event loop and rendering the service unresponsive. The issue is resolved in version 1.11.3 by updating the word-wrapping logic to guarantee forward progress and implementing validation to reject invalid header values like zero or negative widths.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a denial-of-service condition for the target Node.js application. This vulnerability is most dangerous in web applications that reflect user-supplied input into the <code>width</code> parameter of the figlet function. Continuous exploitation can lead to prolonged service outages, impacting availability for all users. The severity is mitigated by the fact that the exploit requires both non-default configuration (<code>whitespaceBreak: true</code>) and access to the function's parameters via untrusted input.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the following actions to mitigate this vulnerability:</p>
<ul>
<li>Upgrade the figlet dependency to version 1.11.3 or later in all projects.</li>
<li>Audit applications utilizing figlet to determine if the <code>width</code> parameter is influenced by untrusted user input.</li>
<li>Disable the <code>whitespaceBreak</code> option if it is not strictly required for business logic, as it remains the primary driver for this vulnerability.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>