Entr'ouvert Lasso Denial-of-Service Vulnerability in SAML Response Handling

Vulnerability

A denial-of-service vulnerability has been identified in Entr'ouvert Lasso version 2.5.1, specifically within the 'lasso_node_init_from_message_with_format' function. This vulnerability arises when a specially crafted SAML response is processed, leading to memory exhaustion and causing a denial-of-service condition. The issue can be triggered by sending a malformed SAML response to the application.

Impact

Exploitation of this vulnerability leads to memory depletion, causing a denial-of-service condition where the application becomes unresponsive or unavailable.

Remediation

Users can update to the patched version of Entr'ouvert Lasso released on August 12, 2025.

Added: Nov 5, 2025, 3:25 PM
Updated: Nov 5, 2025, 5:41 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
8.3
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.