In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade web-push
to version 0.10.4 or higher.
web-push is a web push notification client with support for http-ece encryption and VAPID authentication
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling when processing very large responses in hyper_client.rs
, due to the handling of Content-Length
headers. An attacker can exhaust memory by sending malicious headers.