CVE-2025-46705
7.5Entr'ouvert · Lasso
A denial of service vulnerability in Entr'ouvert Lasso allows unauthenticated attackers to crash the service via a specially crafted SAML assertion response.
Executive summary
A reachable assertion vulnerability in Entr'ouvert Lasso 2.5.1 and 2.8.2 permits unauthenticated remote attackers to cause a denial of service condition.
Vulnerability
The vulnerability is a reachable assertion (CWE-617) triggered within the g_assert_not_reached functionality. An unauthenticated attacker can exploit this by sending a malformed SAML assertion response to the target application.
Business impact
The exploitation of this vulnerability results in a denial of service, which can render authentication services unavailable to legitimate users. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to business continuity, as it could disrupt critical identity federation workflows and prevent access to protected resources.
Remediation
Immediate Action: Monitor the vendor advisories and the Talos Intelligence portal for the release of a patched version of the Lasso library.
Proactive Monitoring: Review web server and application logs for malformed SAML responses or unexpected service crashes that correlate with incoming authentication traffic.
Compensating Controls: Deploy a Web Application Firewall (WAF) configured to inspect and validate SAML assertions, blocking traffic that does not conform to expected schema formats.
Exploitation status
Public Exploit Available: No — exploit_available (unknown).
Analyst recommendation
This vulnerability represents a significant threat to infrastructure reliability because it allows for unauthenticated disruption of service. Organizations currently running the affected versions of Lasso should prioritize the implementation of WAF-based filtering while awaiting an official software update from the vendor. Once a fix is released, testing and deployment should occur during the next available maintenance window to ensure service stability.
Sources
Originally found and disclosed by Discovered by Keane O', Kelley of and another member of Cisco Advanced Security Initiative Group, per the CVE Program record.