CVE-2026-25577

Source
https://cve.org/CVERecord?id=CVE-2026-25577
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25577.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-25577
Aliases
Published
2026-02-10T17:01:26.622Z
Modified
2026-02-12T08:49:10.660402Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Emmett has an Unhandled CookieError Exception Causing Denial of Service
Details

Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.

Database specific
{
    "cwe_ids": [
        "CWE-248",
        "CWE-307"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25577.json"
}
References

Affected packages

Git / github.com/emmett-framework/core

Affected ranges

Type
GIT
Repo
https://github.com/emmett-framework/core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.3.10
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.3.6
v1.3.7
v1.3.8
v1.3.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25577.json"