Impact
The compression middleware creates a zlib stream for each compressed response. If a client aborts the connection while data is still being written, the zlib stream is never destroyed, causing a memory leak (CWE-401), a resource leak (CWE-459), and a missing release of that resource (CWE-772). Over repeated attacks, an unauthenticated attacker can exhaust the process memory and crash the server.
Affected Systems
Any application that includes the compression module before 1.8.2 is vulnerable. The vulnerability affects all Node.js or Express servers that use this middleware for response compression, regardless of internal logic or configuration.
Risk and Exploitability
The CVSS score of 7.5 signals high severity, while the EPSS score of less than 1% indicates a low yet non‑zero exploit probability. An attacker can trigger the flaw by opening a request to a compressed endpoint and terminating it early; repeated attempts drain memory and lead to a system‑wide denial of service. The issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment