AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-87776.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 05, 2026

Disclosure summary

### Impact A vulnerability in compression `< 1.8.2` allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent. When the client aborts the connection before the response finishes, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. Repeated aborted requests can exhaust available memory. All applications using compression are affected. ### Patches Users should upgrade to `1.8.2`. ### Workarounds None.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-vc2v-76pw-4v95

Open original source · Updated Oct 05, 2026

compression vulnerable to Denial of Service via memory leak on premature response close

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
npmcompression< 1.8.21.8.2

Original records & references

PUBLISHED 2026-10-05T19:28:01-04:00
MODIFIED 2026-10-05T19:28:02-04:00
INGESTED 2026-10-06T11:45:33-04:00