Web-Push · Web-Push · CVE-2025-53604
Name of the Vulnerable Software and Affected Versions:
web-push crate versions prior to 0.10.3
Description:
The issue allows an attacker to cause a denial of service condition through excessive memory consumption in the built-in clients of the web-push crate via a large integer in a `Content-Length` header.
Recommendations:
For versions prior to 0.10.3, update to version 0.10.3 or later to resolve the issue. As a temporary workaround, consider restricting the size of the `Content-Length` header to prevent excessive memory consumption.