S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 19, 2025

CVE-2021-3007 Scanner

CVE-2021-3007 Scanner - Remote Code Execution (RCE) vulnerability in Laminas Project laminas-http

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-3007
9.8
CVSS

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Laminas Project provides components for developing high-quality PHP web applications, and laminas-http is a specific package for client and server HTTP utilities. It is widely used by developers to facilitate HTTP requests and responses in PHP applications. Organizations and individuals incorporate laminas-http in their applications to ensure robust HTTP protocol capabilities. Its user base spans across various industries leveraging PHP for their web solutions. Developers rely on its stable and consistent interface to manage HTTP interactions. The package's seamless integration with Zend Framework components enhances its widespread use.

The vulnerability, identified as CVE-2021-3007, is associated with a remote code execution (RCE) flaw within the Laminas Project's laminas-http component. It stems from a deserialization mishap triggered by the destructor method in Zend\Http\Response\Stream. Attackers can exploit this by controlling the content of serialized data, leading to unauthorized code execution. This vulnerability primarily results from inadequate input validation and improper handling of serialized inputs. With this flaw, an attacker can inject and execute arbitrary code on the affected system. It aligned with critical-impact vulnerabilities because it can completely compromise the server's integrity.

Technical details reveal that the deserialization vulnerability resides in the __destruct method of Zend\Http\Response\Stream. Attackers exploit this by inserting specially crafted serialized objects that manipulate the system's processing sequence. The vulnerability primarily targets the PHP serialize and deserialize functionality, making the laminas-http and Zend Framework vulnerable to malicious serialized inputs. The vulnerable parameter orchestrates the system's operational flow, allowing remote code execution when manipulated. Such manipulation can lead to significant unauthorized activities on the affected server. The exploit requires attackers to have control over the serialized data input provided to the HTTP component.

If exploited, this vulnerability allows malicious entities to gain remote access and execute arbitrary code in the context of the server process. The implications include unauthorized server control, data breaches, and potential escalation of privileges. It could also lead to denial of service if attacked repeatedly. As a critical flaw, it exposes the server to a host of malicious activities including the propagation of malware or unauthorized access to sensitive data. Its remote execution nature makes it a severe threat, with widespread potential damage to operations relying on the vulnerable versions.

REFERENCES

Solution Advice
  • Immediately update to laminas-http version 2.14.2 or later to mitigate the risk of exploitation.
  • Audit the affected systems to identify any signs of potential compromise or unauthorized access.
  • Implement strict input validation and sanitization to prevent serialization issues in future developments.
  • Regularly monitor system logs for any unusual or suspicious activity regarding serialized data processing.
  • Consider disabling or restricting unsafe deserialization functions if they are not necessary for your application.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.