CVE-2025-53604 Information

Description

The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header.

Reference

https://crates.io/crates/web-push https://github.com/pimeys/rust-web-push/pull/68 https://rustsec.org/advisories/RUSTSEC-2025-0015.html

CNNVD-202507-523 (Published: 2025-07-04)

Share on: