The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header.Referenceshttps://rustsec.org/advisories/RUSTSEC-2025-0015.htmlhttps://github.com/pimeys/rust-web-push/pull/68https://crates.io/crates/web-push