Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘
🐘 Packagist
Not in CISA KEV
CRITICAL severity

CVE-2021-3007 — zendframework

CRITICALFix: laminas/laminas-http#48

CVE-2021-3007 is a critical-severity (CVSS 9.8) Deserialization of Untrusted Data vulnerability in zendframework/zendframework. 5 public exploit references exist, so weaponization risk is real. A fix is available for zendframework/zendframework — see the affected versions and patch details below.

Remote code execution in zendframework and laminas-http

Also known asGHSA-xx8f-qf9f-5fgw
Published
Updated
Affected
2 pkgs
Patched
1 / 2
Exploits
5 known
Exploitation data as of Oct 9, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
75.3%probability of exploitation in next 30 days
Very High Risk0.00%
Lower risk than most CVEs100th percentile — riskier than 100% of all scored CVEsHighest risk
70.3%79.2%88.2%97.2%90.3%75.3%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2021-3007 by exploitation likelihood (EPSS) against impact (CVSS). In the shaded patch-first corner (EPSS 50%+, CVSS 7.0+).

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the 50–90% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

2 pkgs affected
🐘zendframework/zendframework🐘laminas/laminas-http

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized

Affected Packages

2 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistzendframework/zendframeworkall versionsNo fix
🐘Packagistlaminas/laminas-httpall versions2.14.2composer require laminas/laminas-http:^2.14.2

Affected Products

2 products · 2 configurations
Application
laminas-httpgetlaminas
< 2.14.2
range
Application
zend frameworkzend
1 version
3.0.0
Exploits & PoCs
5

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for zendframework/zendframework, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    No patched version of zendframework/zendframework has shipped for CVE-2021-3007 yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.

  3. Workarounds

    Do not deserialise data from untrusted sources: where the format allows it, restrict deserialisation to an explicit allowlist of expected types, and prefer a data-only format (JSON, Protobuf) over one that can reconstruct arbitrary objects until you can upgrade.

How to detect CVE-2021-3007

A community-maintained Nuclei template exists for this CVE. You can scan for it directly:

nuclei -id cve-2021-3007 -u https://target
Template
Laminas Project laminas-http - Remote Code Execution
Severity
critical
Impact
Attackers can execute arbitrary code remotely by controlling serialized content during deserialization.
Remediation
Update to laminas-http 2.14.2 or later; note that Zend Framework is no longer supported.

Template by ProjectDiscovery nuclei-templates (0xanis), MIT licensed. View the full template. Scan only systems you are authorised to test.

Frequently Asked Questions

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized
O3 Security · Impact-Aware SCA

Is CVE-2021-3007 in your dependencies?

Find it across Packagist, including transitive dependencies.

CVE-2021-3007: zendframework RCE — Fixed in 2.14.2