Vulnerability GHSA-vc2v-76pw-4v95
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
7 hours ago
October 05, 2026 at 11:28 PM UTC
compression vulnerable to Denial of Service via memory leak on premature response close
1.0.0 - 1.8.1
1.0.0 - 1.8.1
Summary
compression vulnerable to Denial of Service via memory leak on premature response close
Details
Impact
A vulnerability in compression < 1.8.2 allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent. When the client aborts the connection before the response finishes, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. Repeated aborted requests can exhaust available memory. All applications using compression are affected.
Patches
Users should upgrade to 1.8.2.
Workarounds
None.
Impacted packages
Timeline
Published
7 hours ago
October 05, 2026 at 11:28 PM UTC
Fixed (1.8.2)
24 days ago
September 11, 2026 at 11:16 AM UTC
Last Modified
7 hours ago
October 05, 2026 at 11:45 PM UTC