
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25577 is a denial-of-service vulnerability in the Emmett web framework's core library (emmett-core) caused by an unhandled CookieError exception when parsing malformed HTTP Cookie headers. It affects all versions of emmett-core up to and including 1.3.10, and was disclosed and patched on February 10, 2026. The vulnerability was reported by researcher Ryu-GeonWoo and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).
The root cause is an uncaught exception (CWE-248 / CWE-703) in the cookies cached property of emmett_core.http.wrappers.Request, located in emmett_core/http/wrappers/__init__.py at line 64. When parsing incoming Cookie headers, the code calls SimpleCookie.load() for each cookie segment without wrapping it in a try/except block; if a cookie name contains illegal characters (e.g., /, (, )), Python's http.cookies module raises a CookieError: Illegal key exception that propagates unhandled up the call stack, resulting in an HTTP 500 response. An unauthenticated attacker can exploit this remotely with no privileges or user interaction required by simply sending a crafted Cookie header — e.g., Cookie: /security=test — to any endpoint of a vulnerable Emmett application. A public proof-of-concept using curl is included in the advisory (GitHub Advisory, Emmett Security Advisory).
Successful exploitation causes HTTP 500 errors on every request that triggers cookie parsing, leading to denial of service and significant performance degradation for all users of the affected application. The advisory notes that after repeated exploitation, the server response time degrades from milliseconds to over 60 seconds per request, effectively rendering the service unusable. There is no confidentiality or integrity impact — the vulnerability is limited to availability (GitHub Advisory).
A public proof-of-concept is included in the official security advisory, requiring only a single curl command with a malformed Cookie header. No authentication, special privileges, or user interaction is required, making exploitation trivially easy for any network-accessible attacker. The EPSS score is approximately 0.053% (0.079% per GitHub Advisory), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (GitHub Advisory, Feedly).
emmett-core <= 1.3.10) using HTTP fingerprinting or dependency scanning tools./, (, )) in the cookie name, such as Cookie: /security=test or Cookie: (security=test.curl http://target:8000/ -H "Cookie:/security=test"cookies property calls SimpleCookie.load(), which raises CookieError: Illegal key '/security'; this propagates unhandled, causing an HTTP 500 response.ERROR in handlers: Application exception followed by a traceback ending in http.cookies.CookieError: Illegal key '<value>'; specifically in emmett_core/http/wrappers/__init__.py at the cookies.load(cookie) line.Cookie headers containing special characters (/, (, ), {, }) in cookie names; HTTP 500 responses returned for these requests.Upgrade emmett-core to version 1.3.11 or later, which wraps the cookies.load() call in a try/except block to catch and silently skip malformed cookie segments. The fix was committed by the maintainer (gi0baro) on February 10, 2026 (Patch Commit). No configuration-based workaround is available; upgrading is the only remediation. Organizations using Emmett-based applications should update the dependency immediately via pip install --upgrade emmett-core (GitHub Advisory).
The vulnerability was reported by security researcher Ryu-GeonWoo and published by the Emmett framework maintainer (gi0baro) on February 10, 2026. Brief coverage appeared on Bluesky via TheHackerWire and on the infinitsec.net security blog shortly after disclosure. No major vendor statements or significant community debate have been observed beyond routine vulnerability database aggregation (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."