Skip to content
Threat Feed
low advisory

Denial of Service via Memory Leak in Node.js compression Middleware

The compression middleware for Node.js is vulnerable to a memory leak leading to Denial of Service when an attacker prematurely closes connections during compressed response transmission.

CVE search metadata

CVE search record: CVE-2026-87776. Severity: high. CVSS: 7.5. EPSS: 0.61%. KEV: no. Product: compression (< 1.8.2). Brief: Denial of Service via Memory Leak in Node.js compression Middleware. Brief link: https://feed.craftedsignal.io/briefs/2026-10-compression-dos/

The npm compression package, a common middleware used in Node.js applications, contains a memory leak vulnerability identified as CVE-2026-87776. The issue exists in versions prior to 1.8.2. When an application utilizes this middleware to compress HTTP responses, the underlying zlib stream object must be properly destroyed upon completion or connection termination. Due to a flaw in how the stream lifecycle is managed, if a client prematurely aborts the connection while the compressed data is being streamed, the zlib stream is not garbage collected and remains in memory.

This behavior is problematic because the leak occurs at the native zlib layer. An attacker can repeatedly send requests to endpoints served by the compression middleware and terminate the connection before the server finishes sending the response. Each such event consumes a small amount of memory, which does not get reclaimed. Consequently, an unauthenticated attacker can perform a sustained, low-bandwidth attack to exhaust the process memory, ultimately causing the Node.js application to crash due to a heap out-of-memory condition.

Impact

Successful exploitation of CVE-2026-87776 results in a Denial of Service for the targeted Node.js application. Because the memory is leaked in the native zlib layer and not immediately managed by the V8 garbage collector, memory exhaustion can occur relatively quickly depending on the number of concurrent connections and the frequency of the attack. All Node.js applications that deploy the compression middleware and expose compressed endpoints are potentially susceptible to service disruption if exposed to the public internet or untrusted networks.

Recommendation

Prioritize the upgrade of the compression package to version 1.8.2 or later to include the fix for CVE-2026-87776. There are no known application-level workarounds that can safely mitigate this behavior without applying the patch.

  • Upgrade compression to 1.8.2 in package.json and redeploy all affected services immediately.
  • Monitor server-side process memory utilization for unexplained upward trends that correlate with high volumes of connection resets.

Immediate actions

Upgrade compression package to 1.8.2 across all Node.js projects

Development 48h

Mitigations

Upgrade compression to 1.8.2

immediate Development

CVE-2026-87776