HIGH
compression
CVE published 2026-09-11
CVE-2026-87776
A remote denial-of-service vulnerability exists in the compression middleware used by Node.js and Express. When a client aborts a connection during a compressed response, the zlib stream is not destroyed, causing a memory leak. Repeated exploitation can lead to server crashes due to memory exhaustion. This issue affects applications using compression, with a high-severity CVSS score of 7.5. Defenders shou [truncated]