CVE-2025-53604: Pimeys Web-Push

Medium severity, CVSS 4.0. EPSS: 0.4% chance of exploitation in the next 30 days.

The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header.

Affected products

  • Pimeys Web-Push: before 0.10.3 (fixed in 0.10.3)

Published 2025-07-05. Last modified 2026-06-17.