Entrouvert maintains Lasso, a web development and integration platform whose vulnerability profile, though concentrated in a single product, leans toward serious outcomes with an elevated share of critical-severity findings. The recurring weakness classes—type confusion, input validation failures, buffer-boundary violations, cryptographic signature verification gaps, and memory-management issues—reflect the memory-safety and input-handling demands of a mature server-side runtime that processes untrusted web requests and handles authentication-critical operations. Defenders deploying Lasso should prioritize patch cycles; live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Entrouvert over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47151CRITICAL A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an | Nov 5, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-46705HIGH A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to | Nov 5, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-46784HIGH A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to | Nov 5, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-46404HIGH A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a d | Nov 5, 2025 | 7.5 | 26 | NO | NO |
CVE-2021-28091HIGH Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. | Jun 4, 2021 | 7.5 | 24 | NO | NO |
CVE-2015-1783HIGH The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitial | Aug 11, 2017 | 7.5 | 22 | NO | NO |
CVE-2009-0050MEDIUM Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain v | Jan 7, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Entrouvert.
Media articles that mention a CVE ID that affects a product developed by Entrouvert — matched by CVE ID, not by vendor name.