Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x6cr-mq53-cc76 Emmett-Core: Unhandled CookieError Exception Causing Denial of Service
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 11 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Feb 2026 17:30:00 +0000

Type Values Removed Values Added
Description Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.
Title Emmett has an Unhandled CookieError Exception Causing Denial of Service
Weaknesses CWE-248
CWE-307
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-11T15:33:08.561Z

Reserved: 2026-02-03T01:02:46.714Z

Link: CVE-2026-25577

cve-icon Vulnrichment

Updated: 2026-02-11T15:32:48.921Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-10T18:16:37.290

Modified: 2026-02-11T16:16:06.200

Link: CVE-2026-25577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses