Entrouvert
Entrouvert Lasso: vulnerabilities and CVEs
Entrouvert Lasso has 8 published vulnerabilities, 5 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months5
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28156 | High (8.5) | 0.36% | — | Aug 13, 2026 | Subscriber SQL Injection in Do Lasso <= 358 versions. |
| CVE-2025-47151 | Critical (9.8) | 1.1% | — | Nov 5, 2025 | A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker… |
| CVE-2025-46784 | High (7.5) | 0.59% | — | Nov 5, 2025 | A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in… |
| CVE-2025-46705 | High (7.5) | 0.57% | — | Nov 5, 2025 | A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can… |
| CVE-2025-46404 | High (7.5) | 0.59% | — | Nov 5, 2025 | A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send… |
| CVE-2021-28091 | High (7.5) | 1.3% | — | Jun 4, 2021 | Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. |
| CVE-2015-1783 | High (7.5) | 3.5% | — | Aug 11, 2017 | The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application… |
| CVE-2009-0050 | Medium (4.3) | 1.3% | — | Jan 7, 2009 | Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.