Lasso
Vendor:
First CVE: Jan 7, 2009 · Active for 17 years
7
Total CVEs
More Total CVEs than 83% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Lasso over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 7, 2009
17 years ago
Most Recent CVE
Nov 5, 2025
261 days ago
CVE Severity & Scoring
Lasso7 CVEs
14%
71%
14%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (85.7%)
Unknown1 (14.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High0 (0.0%)
Unknown1 (14.3%)
User Interaction
None6 (85.7%)
Unknown1 (14.3%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (85.7%)
Unknown1 (14.3%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47151CRITICAL A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an | Nov 5, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-46705HIGH A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to | Nov 5, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-46784HIGH A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to | Nov 5, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-46404HIGH A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a d | Nov 5, 2025 | 7.5 | 26 | NO | NO |
CVE-2021-28091HIGH Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. | Jun 4, 2021 | 7.5 | 24 | NO | NO |
CVE-2015-1783HIGH The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitial | Aug 11, 2017 | 7.5 | 22 | NO | NO |
CVE-2009-0050MEDIUM Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain v | Jan 7, 2009 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Lasso
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.8.2 | 2 | 8.7 | 0.6% | 0 | 0 |
| 2.5.1 | 4 | 8.1 | 0.5% | 0 | 0 |
| 2.0.0-1 | 1 | 4.3 | 1.3% | 0 | 0 |
| 1.9.9.0 | 1 | 4.3 | 1.3% | 0 | 0 |