Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11. | |
| Title | Emmett has an Unhandled CookieError Exception Causing Denial of Service | |
| Weaknesses | CWE-248 CWE-307 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-10T17:01:26.622Z
Reserved: 2026-02-03T01:02:46.714Z
Link: CVE-2026-25577
No data.
Status : Received
Published: 2026-02-10T18:16:37.290
Modified: 2026-02-10T18:16:37.290
Link: CVE-2026-25577
No data.
OpenCVE Enrichment
No data.