compression vulnerable to Denial of Service via memory leak on premature response close
Description
Published by the National Vulnerability Database
Sep 11, 2026
Published to the GitHub Advisory Database
Oct 5, 2026
Reviewed
Oct 5, 2026
Last updated
Oct 5, 2026
Impact
A vulnerability in compression
< 1.8.2allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent. When the client aborts the connection before the response finishes, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. Repeated aborted requests can exhaust available memory. All applications using compression are affected.Patches
Users should upgrade to
1.8.2.Workarounds
None.
References