Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20100 | Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header |
Github GHSA |
GHSA-287x-9rff-qvcg | Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 05 Jul 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header. | |
| Weaknesses | CWE-130 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-08T14:35:55.692Z
Reserved: 2025-07-05T00:00:00.000Z
Link: CVE-2025-53604
Updated: 2025-07-08T14:35:03.913Z
Status : Deferred
Published: 2025-07-05T01:15:28.340
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-53604
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA