CVE-2025-46705

Published Nov 5, 2025

Last updated 6 months ago

Overview

Description
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
Source
talos-cna@cisco.com
NVD status
Analyzed
Products
lasso

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

talos-cna@cisco.com
CWE-617

Social media

Hype score
Not currently trending
  1. 🚨 URGENT SECURITY UPDATE for #Fedora 41 Users 🚨A critical buffer overflow (CVE-2025-46705) has been patched in the Lasso #SAML library. This high-severity flaw could allow remote code execution. Read more: 👉 https://t.co/nXjg7Rj3Ia #securi

    @Cezar_H_Linux

    14 Nov 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-46705 (CVSS:7.5, HIGH) is Analyzed. A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2...https://t.co/x5vzpDvdK3 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    10 Nov 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. [CVE-2025-46705: CRITICAL] Denial of service flaw in Entr'ouvert Lasso 2.5.1 and 2.8.2 allows attack via crafted SAML assertion responses to trigger issues in g_assert_not_reached functionality.#cve,CVE-2025-46705,#cybersecurity https://t.co/ez3RX9WsXy https://t.co/JQb2Lq8In7

    @CveFindCom

    5 Nov 2025

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-46705 pertains to a **denial of service (DoS)** vulnerability within the Entr’ouvert Lasso versions 2.5.1 and 2.8.2. The issue stems from a flaw in the `g_assert_not_reached` functionality which is used as an assertion check within the application. Specifically, this

    @CveTodo

    5 Nov 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-46705 A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion respon… https://t.co/eGkEQ5B4er

    @CVEnew

    5 Nov 2025

    206 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations