A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade lassoUpgrade lasso-debuginfoUpgrade lasso-develUpgrade python3-lasso | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade lasso | Nov 10, 2025 | Nov 10, 2025 |
| Suse | — | Upgrade python3-lassoUpgrade liblasso-develUpgrade liblasso3 | Dec 5, 2025 | Nov 13, 2025 |
| Ubuntu | — | Upgrade python3-lassoUpgrade liblasso-perlUpgrade liblasso3t64Upgrade liblasso3 | Nov 19, 2025 | Nov 5, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Feb 9, 2026 | Nov 5, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub