A denial of service vulnerability exists in the...
Critical severity
Unreviewed
Published
Nov 5, 2025
to the GitHub Advisory Database
•
Updated Nov 5, 2025
Description
Published by the National Vulnerability Database
Nov 5, 2025
Published to the GitHub Advisory Database
Nov 5, 2025
Last updated
Nov 5, 2025
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
References