← العودة للجدول
CVE-2026-96780
CVE-2026-96780 — figlet is vulnerable to denial of service via unbounded loop when whitespaceBrea
📅 2026-10-03
🟠 High 🔥 No GHSA Vulnerability Vulnerability

📋 الوصف الكامل

### Impact A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when **both**: - `whitespaceBreak: true` is set, **and** - `width` is set smaller than the rendered width of a single FIGlet character. Under these conditions `breakWord()` could never find a valid break point, so the word-wrapping loop in `generateFigTextLines()` never terminated. This pins a CPU core and grows me

💻 الأنظمة المتأثرة

Node.js

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-96780

📡 المصدر

GHSA

✅ الحلول والتخفيف

Update to v1.11.3

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←