Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.
History

Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Emmett-framework
Emmett-framework core
Vendors & Products Emmett-framework
Emmett-framework core

Wed, 11 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Feb 2026 17:30:00 +0000

Type Values Removed Values Added
Description Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.
Title Emmett has an Unhandled CookieError Exception Causing Denial of Service
Weaknesses CWE-248
CWE-307
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-02-10T17:01:26.622Z

Updated: 2026-02-11T15:33:08.561Z

Reserved: 2026-02-03T01:02:46.714Z

Link: CVE-2026-25577

cve-icon Vulnrichment

Updated: 2026-02-11T15:32:48.921Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-10T18:16:37.290

Modified: 2026-02-11T16:16:06.200

Link: CVE-2026-25577

cve-icon Redhat

No data.