Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header
Moderate severity
GitHub Reviewed
Published
Jul 5, 2025
to the GitHub Advisory Database
•
Updated Jul 7, 2025
Description
Published by the National Vulnerability Database
Jul 5, 2025
Published to the GitHub Advisory Database
Jul 5, 2025
Reviewed
Jul 7, 2025
Last updated
Jul 7, 2025
The web-push crate before 0.10.4 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header. The patch was initially made available in version 0.10.3, but version 0.10.3 has since been yanked.
References