{"id":"GHSA-86r3-4gq8-xw8q","summary":"Remote Code Execution in Laravel","details":"## Withdrawn\nThis advisory has been withdrawn because it is not a security issue and the CVE has been revoked.\n\n## Original Description\nA Remote Code Execution (RCE) vulnerability exists in h laravel 5.8.38 via an unserialize pop chain in (1) __destruct in \\Routing\\PendingResourceRegistration.php, (2) __cal in Queue\\Capsule\\Manager.php, and (3) __invoke in mockery\\library\\Mockery\\ClosureWrapper.php.","aliases":["CVE-2021-43503"],"modified":"2026-09-10T03:49:28.653090647Z","published":"2022-04-09T00:00:25Z","withdrawn":"2022-08-22T16:34:29Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-04-12T20:32:12Z","nvd_published_at":"2022-04-08T18:15:00Z","cwe_ids":["CWE-502"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43503"},{"type":"WEB","url":"https://github.com/1nhann/vulns/issues/1#issuecomment-1213126338"},{"type":"WEB","url":"https://github.com/guoyanan1g/Laravel-vul/issues/2#issue-1045655892"}],"affected":[{"package":{"name":"laravel/laravel","ecosystem":"Packagist","purl":"pkg:composer/laravel/laravel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"5.8.38"}]}],"versions":["v4.0.0","v4.0.0-BETA3","v4.0.0-BETA4","v4.0.4","v4.0.5","v4.0.6","v4.0.7","v4.0.8","v4.0.9","v4.1.0","v4.1.18","v4.1.27","v4.2.0","v4.2.11","v5.0.0","v5.0.1","v5.0.16","v5.0.22","v5.1.0","v5.1.1","v5.1.11","v5.1.3","v5.1.33","v5.1.4","v5.2.0","v5.2.15","v5.2.23","v5.2.24","v5.2.27","v5.2.29","v5.2.31","v5.3.0","v5.3.10","v5.3.16","v5.3.30","v5.4.0","v5.4.15","v5.4.16","v5.4.19","v5.4.21","v5.4.23","v5.4.3","v5.4.30","v5.4.9","v5.5.0","v5.5.22","v5.5.28","v5.6.0","v5.6.12","v5.6.21","v5.6.33","v5.6.7","v5.7.0","v5.7.13","v5.7.15","v5.7.19","v5.7.28","v5.8.0","v5.8.16","v5.8.17","v5.8.3","v5.8.35"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-86r3-4gq8-xw8q/GHSA-86r3-4gq8-xw8q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}