CVE-2026-25577Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-10); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-11: 102-1002-11
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-02-111
General1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25577 Emmett Framework Denial of Service via Malformed Cookie Header Parsing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25577

    Post summary

    A short reference to a Denial of Service vulnerability in the Emmett Framework caused by malformed cookie header parsing, with no further details on PoC, exploitation, or remediation.

    0001085
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25577: Crumbs in the Gearbox: Crashing Emmett Framework with Malformed Cookies A classic input validation oversight in the Emmett Python web framework allows unauthenticated attackers to trigger unhandled exceptions by sending malformed HTTP ... https://cvereports.com/reports/CVE-2026-25577

    Post summary

    The report discloses a classic input validation flaw in the Emmett Python framework that lets unauthenticated attackers trigger unhandled exceptions by sending malformed HTTP requests; no PoC, exploit, patch, or active exploitation details are provided.

    0000023
    27 followersView on X

Explore more