The vulnerability occurs when the cookie is part of the compression payload. Although that does depend on the attacker being able to control what gets sent.