<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Compression (&lt; 1.8.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/compression--1.8.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:45:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/compression--1.8.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service via Memory Leak in Node.js compression Middleware</title><link>https://feed.craftedsignal.io/briefs/2026-10-compression-dos/</link><pubDate>Tue, 06 Oct 2026 00:45:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-compression-dos/</guid><description>The compression middleware for Node.js is vulnerable to a memory leak leading to Denial of Service when an attacker prematurely closes connections during compressed response transmission.</description><content:encoded><![CDATA[<p>The npm compression package, a common middleware used in Node.js applications, contains a memory leak vulnerability identified as CVE-2026-87776. The issue exists in versions prior to 1.8.2. When an application utilizes this middleware to compress HTTP responses, the underlying zlib stream object must be properly destroyed upon completion or connection termination. Due to a flaw in how the stream lifecycle is managed, if a client prematurely aborts the connection while the compressed data is being streamed, the zlib stream is not garbage collected and remains in memory.</p>
<p>This behavior is problematic because the leak occurs at the native zlib layer. An attacker can repeatedly send requests to endpoints served by the compression middleware and terminate the connection before the server finishes sending the response. Each such event consumes a small amount of memory, which does not get reclaimed. Consequently, an unauthenticated attacker can perform a sustained, low-bandwidth attack to exhaust the process memory, ultimately causing the Node.js application to crash due to a heap out-of-memory condition.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-87776 results in a Denial of Service for the targeted Node.js application. Because the memory is leaked in the native zlib layer and not immediately managed by the V8 garbage collector, memory exhaustion can occur relatively quickly depending on the number of concurrent connections and the frequency of the attack. All Node.js applications that deploy the compression middleware and expose compressed endpoints are potentially susceptible to service disruption if exposed to the public internet or untrusted networks.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the upgrade of the compression package to version 1.8.2 or later to include the fix for CVE-2026-87776. There are no known application-level workarounds that can safely mitigate this behavior without applying the patch.</p>
<ul>
<li>Upgrade <code>compression</code> to 1.8.2 in <code>package.json</code> and redeploy all affected services immediately.</li>
<li>Monitor server-side process memory utilization for unexplained upward trends that correlate with high volumes of connection resets.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>nodejs</category><category>middleware</category><category>vulnerability</category></item></channel></rss>