{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anodejscompressionnode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nodejs:compression:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-87776"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["compression (\u003c 1.8.2)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","nodejs","middleware","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Node.js Foundation"],"content_html":"\u003cp\u003eThe npm compression package, a common middleware used in Node.js applications, contains a memory leak vulnerability identified as CVE-2026-87776. The issue exists in versions prior to 1.8.2. When an application utilizes this middleware to compress HTTP responses, the underlying zlib stream object must be properly destroyed upon completion or connection termination. Due to a flaw in how the stream lifecycle is managed, if a client prematurely aborts the connection while the compressed data is being streamed, the zlib stream is not garbage collected and remains in memory.\u003c/p\u003e\n\u003cp\u003eThis behavior is problematic because the leak occurs at the native zlib layer. An attacker can repeatedly send requests to endpoints served by the compression middleware and terminate the connection before the server finishes sending the response. Each such event consumes a small amount of memory, which does not get reclaimed. Consequently, an unauthenticated attacker can perform a sustained, low-bandwidth attack to exhaust the process memory, ultimately causing the Node.js application to crash due to a heap out-of-memory condition.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-87776 results in a Denial of Service for the targeted Node.js application. Because the memory is leaked in the native zlib layer and not immediately managed by the V8 garbage collector, memory exhaustion can occur relatively quickly depending on the number of concurrent connections and the frequency of the attack. All Node.js applications that deploy the compression middleware and expose compressed endpoints are potentially susceptible to service disruption if exposed to the public internet or untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of the compression package to version 1.8.2 or later to include the fix for CVE-2026-87776. There are no known application-level workarounds that can safely mitigate this behavior without applying the patch.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ecompression\u003c/code\u003e to 1.8.2 in \u003ccode\u003epackage.json\u003c/code\u003e and redeploy all affected services immediately.\u003c/li\u003e\n\u003cli\u003eMonitor server-side process memory utilization for unexplained upward trends that correlate with high volumes of connection resets.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:45:48Z","date_published":"2026-10-06T00:45:48Z","id":"https://feed.craftedsignal.io/briefs/2026-10-compression-dos/","summary":"The compression middleware for Node.js is vulnerable to a memory leak leading to Denial of Service when an attacker prematurely closes connections during compressed response transmission.","title":"Denial of Service via Memory Leak in Node.js compression Middleware","url":"https://feed.craftedsignal.io/briefs/2026-10-compression-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:nodejs:compression:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}