PT-2025-28030 · Web-Push · Web-Push

Niklasf

·

Published

2025-02-16

·

Updated

2025-07-05

·

CVE-2025-53604

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: web-push crate versions prior to 0.10.3
Description: The issue allows an attacker to cause a denial of service condition through excessive memory consumption in the built-in clients of the web-push crate via a large integer in a Content-Length header.
Recommendations: For versions prior to 0.10.3, update to version 0.10.3 or later to resolve the issue. As a temporary workaround, consider restricting the size of the Content-Length header to prevent excessive memory consumption.

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-53604
GHSA-287X-9RFF-QVCG
GHSA-FC83-9JWQ-GC2M
RUSTSEC-2025-0015

Affected Products

Web-Push