CVE-2025-53604
MEDIUMWeb-Push <0.10.3 - DoS
Title source: llmDescription
The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header.
Scores
CVSS v3
4.0
EPSS
0.0006
EPSS Percentile
17.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L
Classification
CWE
CWE-130
Status
draft
Affected Products (1)
crates.io/web-push
< 0.10.4crates.io
Timeline
Published
Jul 05, 2025
Tracked Since
Feb 18, 2026