CVE-2025-53604: Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header
(updated )
The web-push crate before 0.10.4 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header. The patch was initially made available in version 0.10.3, but version 0.10.3 has since been yanked.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-53604 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →