CVE-2021-3007 is a critical-severity (CVSS 9.8) Deserialization of Untrusted Data vulnerability in zendframework/zendframework. 5 public exploit references exist, so weaponization risk is real. A fix is available for zendframework/zendframework — see the affected versions and patch details below.
Remote code execution in zendframework and laminas-http
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2021-3007 by exploitation likelihood (EPSS) against impact (CVSS). In the shaded patch-first corner (EPSS 50%+, CVSS 7.0+).
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the 50–90% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
zendframework/zendframework🐘laminas/laminas-httpReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | zendframework/zendframework | all versions | No fix |
| 🐘Packagist | laminas/laminas-http | all versions | 2.14.2composer require laminas/laminas-http:^2.14.2 |
Affected Products
laminas-httpgetlaminaszend frameworkzendResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, ha…
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, ha…
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, ha…
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, ha…
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, ha…
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for zendframework/zendframework, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
No patched version of zendframework/zendframework has shipped for CVE-2021-3007 yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.
Workarounds
Do not deserialise data from untrusted sources: where the format allows it, restrict deserialisation to an explicit allowlist of expected types, and prefer a data-only format (JSON, Protobuf) over one that can reconstruct arbitrary objects until you can upgrade.
How to detect CVE-2021-3007
A community-maintained Nuclei template exists for this CVE. You can scan for it directly:
nuclei -id cve-2021-3007 -u https://target- Template
- Laminas Project laminas-http - Remote Code Execution
- Severity
- critical
- Impact
- Attackers can execute arbitrary code remotely by controlling serialized content during deserialization.
- Remediation
- Update to laminas-http 2.14.2 or later; note that Zend Framework is no longer supported.
Template by ProjectDiscovery nuclei-templates (0xanis), MIT licensed. View the full template. Scan only systems you are authorised to test.
Frequently Asked Questions
Is CVE-2021-3007 in your dependencies?
Find it across Packagist, including transitive dependencies.