OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-87776: compression vulnerable to Denial of Service via memory leak on premature response close

GitHub Advisories · officialPublished Oct 5, 2026Risk 37/100

### Impact A vulnerability in compression `< 1.8.2` allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent. When the client aborts the connection before the response finishes, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. Repeated aborted requests can exhaust available memory. All applications using compression are affected. ### Patches Users should upgrade to `1.8.2`. ### Workarounds None.

Upgrade affected packages to a patched version: compression 1.8.2.

Vendor
Not specified
Product
compression
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source