Back

HIGH

compression vulnerable to Denial of Service via memory leak on premature response close

Published Sep 11, 2026

Description

compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote unauthenticated attacker can repeatedly open requests and disconnect early, exhausting the available memory and crashing the server. All applications using compression are affected. The issue is fixed in compression 1.8.2, and users should upgrade to 1.8.2 or later.

Affected products

Remediation

Red Hat statement

Red Hat has rated this vulnerability as Important. A remote unauthenticated attacker can cause a denial of service by repeatedly aborting connections while compressed responses are being sent, which can lead to memory exhaustion and server termination.

Red Hat mitigation

Update the compression middleware to version 1.8.2 or later. No supported workaround is currently available if the affected version cannot be updated.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner openjs
Published Sep 11, 2026
Updated Sep 11, 2026
Reserved Sep 9, 2026
CISA Vulnrichment
Updated Sep 11, 2026
NVD
Status Awaiting Analysis
Modified Sep 16, 2026
Red Hat
Severity Important
Public date Sep 11, 2026
ENISA EUVD
Assigner openjs
Published Sep 11, 2026
Updated Sep 11, 2026
Exploited since n/a
EUVD-2026-76072 GHSA-VC2V-76PW-4V95