PT-2025-28030 · Web-Push · Web-Push
Niklasf
·
Published
2025-02-16
·
Updated
2025-07-05
·
CVE-2025-53604
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
web-push crate versions prior to 0.10.3
Description:
The issue allows an attacker to cause a denial of service condition through excessive memory consumption in the built-in clients of the web-push crate via a large integer in a
Content-Length header.Recommendations:
For versions prior to 0.10.3, update to version 0.10.3 or later to resolve the issue. As a temporary workaround, consider restricting the size of the
Content-Length header to prevent excessive memory consumption.Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Web-Push