# CVE-2026-25577

## Summary

- **CVE ID:** CVE-2026-25577
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-248, CWE-307
- **Published:** Feb 10, 2026
- **Last Modified:** Mar 12, 2026

## Description

Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.

## Affected Products

- emmett-framework — core (< 1.3.11)

## References

- [CNA](https://github.com/emmett-framework/core/security/advisories/GHSA-x6cr-mq53-cc76)
- [CNA](https://github.com/emmett-framework/core/commit/9557ea23a27cbadf7774d8bca6bbe4b54fa8a3ec)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.28%
- **EPSS Percentile:** 19.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._