A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality...
Vulnerability Description
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-46404
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Discovered by Keane O'Kelley of and another member of Cisco Advanced Security Initiative Group
More from Entr'ouvert
View All →Affected Vendor
Entr'ouvert
View all reports →