MEDIUM4.0
GHSA-287x-9rff-qvcg
Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header
Details
The web-push crate before 0.10.4 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header. The patch was initially made available in version 0.10.3, but version 0.10.3 has since been yanked.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/web-push
Introduced in:
0Fixed in: 0.10.4Upgrade web-push to 0.10.4 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-53604[ADVISORY]
- https://github.com/pimeys/rust-web-push/pull/68[WEB]
- https://github.com/pimeys/rust-web-push/commit/8447ed86bf3f24629abd7022b94104bf3cd64453[WEB]
- https://crates.io/crates/web-push[WEB]
- https://github.com/pimeys/rust-web-push[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2025-0015.html[WEB]