GHSA-vc2v-76pw-4v95

Suggest an improvement
Source
https://github.com/advisories/GHSA-vc2v-76pw-4v95
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-vc2v-76pw-4v95/GHSA-vc2v-76pw-4v95.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vc2v-76pw-4v95
Aliases
Published
2026-10-05T23:28:01Z
Modified
2026-10-05T23:45:07Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
compression vulnerable to Denial of Service via memory leak on premature response close
Details

Impact

A vulnerability in compression < 1.8.2 allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent. When the client aborts the connection before the response finishes, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. Repeated aborted requests can exhaust available memory. All applications using compression are affected.

Patches

Users should upgrade to 1.8.2.

Workarounds

None.

Database specific
{
    "cwe_ids":  [
        "CWE-401",
        "CWE-459"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T23:28:01Z",
    "nvd_published_at":  "2026-09-11T12:16:52Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / compression

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.8.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-vc2v-76pw-4v95/GHSA-vc2v-76pw-4v95.json"