VDB
Sign up
MEDIUM4.0

GHSA-287x-9rff-qvcg

Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header

Details

The web-push crate before 0.10.4 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header. The patch was initially made available in version 0.10.3, but version 0.10.3 has since been yanked.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/web-push
Introduced in: 0Fixed in: 0.10.4

Upgrade web-push to 0.10.4 or newer (ecosystem crates.io).

References