CVE-2025-46705: High severity Entr'ouvert Lasso vulnerability
Published Nov 5, 2025
·Updated
A denial of service vulnerability exists in the gassertnotreached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
Affected Software
3 affected components
Entr'ouvert Lasso>=2.5.1<=2.8.2
Entrouvert Lasso=2.5.1
Entrouvert Lasso=2.8.2
Event History
Nov 5, 2025
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-46705?
CVE-2025-46705 is classified as a denial of service vulnerability, which can disrupt service availability.
2
How do I fix CVE-2025-46705?
To mitigate CVE-2025-46705, upgrade Entr'ouvert Lasso to a version later than 2.8.2.
3
What products are affected by CVE-2025-46705?
CVE-2025-46705 affects Entr'ouvert Lasso versions 2.5.1 to 2.8.2.
4
What type of attack can exploit CVE-2025-46705?
An attacker can exploit CVE-2025-46705 by sending a specially crafted malformed SAML assertion response.
5
What conditions trigger CVE-2025-46705?
CVE-2025-46705 can be triggered when an application calls the g_assert_not_reached function with invalid input.