CVE-2025-53604
MEDIUMweb-push < 0.10.3 - Denial of Service via Large Content-Length Header
Title source: llmDescription
The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header.
References (3)
Core 3
Core References
Various Sources
https://crates.io/crates/web-push
Various Sources
https://rustsec.org/advisories/RUSTSEC-2025-0015.html
Issue Tracking
https://github.com/pimeys/rust-web-push/pull/68
Scores
CVSS v3
4.0
EPSS
0.0033
EPSS Percentile
24.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-130
Status
published
Products (2)
crates.io/web-push
0 - 0.10.4crates.io
pimeys/web-push
< 0.10.3
Published
Jul 05, 2025
Tracked Since
Feb 18, 2026