laminas/laminas-diactoros
PSR HTTP Message implementations
Activity
- Latest release
- 11mo ago
- Total releases
- 148
- Cadence
- ~10 days
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- Dec 31, 2019
| Version | Released | |
|---|---|---|
3.8.0
minor
|
3.8.0
minor
Dependencies (2)
Changelog
Compare changes
|
|
3.7.0
minor
| ||
3.6.0
minor
| ||
3.5.0
minor
| ||
3.4.0
minor
| ||
3.3.1
patch
| ||
2.26.0
minor
| ||
3.3.0
minor
| ||
3.2.0
minor
| ||
3.1.0
minor
| ||
3.0.0
major
| ||
2.23.1
patch
| ||
2.24.2
patch
| ||
2.21.1
patch
| ||
2.22.1
patch
| ||
2.25.2
patch
| ||
2.19.1
patch
| ||
2.20.1
patch
| ||
2.18.1
patch
| ||
2.25.1
patch
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.24.1
patch
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.25.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.24.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.23.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.22.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.21.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.20.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.19.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.18.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.17.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.16.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.15.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.14.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.13.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.12.0
minor
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.11.3
patch
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.11.2
patch
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.11.1
patch
1 CVE
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.11.0
minor
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.10.0
minor
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.9.2
patch
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.9.1
patch
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.9.0
minor
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.8.0
minor
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.7.0
minor
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.6.0
minor
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.5.1
patch
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.5.0
minor
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.4.1
patch
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.4.0
minor
2 CVEs
CVE-2023-29530
GHSA-xv3h-4844-9h36
Apr 24, 2023
HTTP Multiline Header Termination
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAffected versions of Laminas Diactoros accepted a single line feed (LF / PatchesThe problem has been patched in the following versions:
WorkaroundsValidate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling References
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 117 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
Fixed in
2.18.1
2.19.1
2.20.1
2.21.1
2.22.1
2.23.1
2.24.2
2.25.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-31109
GHSA-8274-h5jp-97vr
Jul 27, 2022
Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactApplications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a PatchesAny version after 2.11.0. Starting in laminas/laminas-diactoros 2.11.1, we have added The primary use case of the interface is to allow modifying the generated URI based on the presence of headers such as Due to potential security issues, it is generally best to only accept these headers if you trust the reverse proxy that has initiated the request.
(This value is found in
WorkaroundsInfrastructure or DevOps can configure web servers to reject Users of laminas/laminas-diactoros can make use of the ReferencesFor more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
+ 98 more Show less
1.2.1
1.3.0
1.3.1
1.3.10
1.3.11
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.8.0
1.8.0p1
1.8.0p2
1.8.1
1.8.1p1
1.8.1p2
1.8.2
1.8.2p1
1.8.2p2
1.8.3
1.8.3p1
1.8.3p2
1.8.4
1.8.4p1
1.8.4p2
1.8.5
1.8.5p1
1.8.5p2
1.8.6
1.8.6p1
1.8.6p2
1.8.7
1.8.7p1
1.8.7p2
2.0.0
2.0.0p1
2.0.0p2
2.0.1
2.0.1p1
2.0.1p2
2.0.2
2.0.2p1
2.0.2p2
2.0.3
2.0.3p1
2.0.3p2
2.1.0
2.1.0p1
2.1.0p2
2.1.1
2.1.1p1
2.1.1p2
2.1.2
2.1.2p1
2.1.2p2
2.1.3
2.1.3p1
2.1.3p2
2.1.4
2.1.4p1
2.1.4p2
2.1.5
2.1.5p1
2.1.5p2
2.10.0
2.11.0
2.2.0
2.2.0p1
2.2.0p2
2.2.1
2.2.1p1
2.2.1p2
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.9.2
Fixed in
2.11.1
References
Updated Nov 08, 2023 · Source: OSV.dev |