A high-severity vulnerability affecting compression versions < 1.8.2, CVE-2026-87776 with a CVSS score of 7.5, affects compression functionality in applications using zlib streams for data compression. The flaw allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent, resulting in memory leaks due to premature zlib stream destruction. This can exhaust available memory and impact business operations as repeated aborted requests can lead to resource depletion.
We recommend you to update compression to version 1.8.2.[/subscribe_to_unlock_form]
A high-severity vulnerability affecting compression versions < 1.8.2, CVE-2026-87776 with a CVSS score of 7.5, affects compression functionality in applications using zlib streams for data compression. The flaw allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent, resulting in memory leaks due to premature zlib stream destruction. This can exhaust available memory and impact business operations as repeated aborted requests can lead to resource depletion.
We recommend you to update compression to version 1.8.2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]