PatchSiren

compression CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH compression CVE published 2026-09-11

CVE-2026-87776

A remote denial-of-service vulnerability exists in the compression middleware used by Node.js and Express. When a client aborts a connection during a compressed response, the zlib stream is not destroyed, causing a memory leak. Repeated exploitation can lead to server crashes due to memory exhaustion. This issue affects applications using compression, with a high-severity CVSS score of 7.5. Defenders shou [truncated]