Threat Advisory

Compression Flaw Allows Denial of Service via Memory Leak

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability affecting compression versions < 1.8.2, CVE-2026-87776 with a CVSS score of 7.5, affects compression functionality in applications using zlib streams for data compression. The flaw allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent, resulting in memory leaks due to premature zlib stream destruction. This can exhaust available memory and impact business operations as repeated aborted requests can lead to resource depletion.

RECOMMENDATION:

We recommend you to update compression to version 1.8.2.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability affecting compression versions < 1.8.2, CVE-2026-87776 with a CVSS score of 7.5, affects compression functionality in applications using zlib streams for data compression. The flaw allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent, resulting in memory leaks due to premature zlib stream destruction. This can exhaust available memory and impact business operations as repeated aborted requests can lead to resource depletion.

RECOMMENDATION:

We recommend you to update compression to version 1.8.2.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu