« Back to list

Entrouvert

Entrouvert Lasso: vulnerabilities and CVEs

Entrouvert Lasso has 8 published vulnerabilities, 5 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months5
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-28156High (8.5)0.36%—Aug 13, 2026
Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2025-47151Critical (9.8)1.1%—Nov 5, 2025
A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker…
CVE-2025-46784High (7.5)0.59%—Nov 5, 2025
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in…
CVE-2025-46705High (7.5)0.57%—Nov 5, 2025
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can…
CVE-2025-46404High (7.5)0.59%—Nov 5, 2025
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send…
CVE-2021-28091High (7.5)1.3%—Jun 4, 2021
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
CVE-2015-1783High (7.5)3.5%—Aug 11, 2017
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application…
CVE-2009-0050Medium (4.3)1.3%—Jan 7, 2009
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application4
  2. T1499.004 Application or System Exploitation3
  3. T1005 Data from Local System1
  4. T1059 Command and Scripting Interpreter1
  5. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.