{"id":"GHSA-vv7q-mfpc-qgm5","summary":"Unserialized Pop Chain in Laravel","details":"## Withdrawn\nThis advisory has been withdrawn because it is not a security issue and the CVE has been revoked.\n\n## Original Description\nLaravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution (RCE) via an unserialized pop chain in __destruct in Illuminate\\Broadcasting\\PendingBroadcast.php and __call in Faker\\Generator.php.","aliases":["CVE-2022-31279"],"modified":"2026-09-10T03:49:44.227283148Z","published":"2022-06-08T00:00:43Z","withdrawn":"2022-08-22T16:36:48Z","database_specific":{"github_reviewed_at":"2022-06-08T22:27:54Z","nvd_published_at":"2022-06-07T16:15:00Z","cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31279"},{"type":"WEB","url":"https://github.com/1nhann/vulns/issues/1#issuecomment-1213126338"},{"type":"WEB","url":"https://github.com/1nhann/vulns/issues/3"},{"type":"WEB","url":"https://github.com/ambionics/phpggc/issues/118"},{"type":"PACKAGE","url":"https://github.com/laravel/laravel"},{"type":"WEB","url":"https://inhann.top/2022/05/17/bypass_wakeup"}],"affected":[{"package":{"name":"laravel/laravel","ecosystem":"Packagist","purl":"pkg:composer/laravel/laravel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"9.1.8"}]}],"versions":["v4.0.0","v4.0.0-BETA3","v4.0.0-BETA4","v4.0.4","v4.0.5","v4.0.6","v4.0.7","v4.0.8","v4.0.9","v4.1.0","v4.1.18","v4.1.27","v4.2.0","v4.2.11","v5.0.0","v5.0.1","v5.0.16","v5.0.22","v5.1.0","v5.1.1","v5.1.11","v5.1.3","v5.1.33","v5.1.4","v5.2.0","v5.2.15","v5.2.23","v5.2.24","v5.2.27","v5.2.29","v5.2.31","v5.3.0","v5.3.10","v5.3.16","v5.3.30","v5.4.0","v5.4.15","v5.4.16","v5.4.19","v5.4.21","v5.4.23","v5.4.3","v5.4.30","v5.4.9","v5.5.0","v5.5.22","v5.5.28","v5.6.0","v5.6.12","v5.6.21","v5.6.33","v5.6.7","v5.7.0","v5.7.13","v5.7.15","v5.7.19","v5.7.28","v5.8.0","v5.8.16","v5.8.17","v5.8.3","v5.8.35","v6.0.0","v6.0.1","v6.0.2","v6.12.0","v6.18.0","v6.18.3","v6.18.35","v6.18.8","v6.19.0","v6.2.0","v6.20.0","v6.20.1","v6.4.0","v6.5.2","v6.8.0","v7.0.0","v7.12.0","v7.25.0","v7.28.0","v7.29.0","v7.3.0","v7.30.0","v7.30.1","v7.6.0","v8.0.0","v8.0.1","v8.0.2","v8.0.3","v8.1.0","v8.2.0","v8.3.0","v8.4.0","v8.4.1","v8.4.2","v8.4.3","v8.4.4","v8.5.0","v8.5.1","v8.5.10","v8.5.11","v8.5.12","v8.5.13","v8.5.14","v8.5.15","v8.5.16","v8.5.17","v8.5.18","v8.5.19","v8.5.2","v8.5.20","v8.5.21","v8.5.22","v8.5.23","v8.5.24","v8.5.3","v8.5.4","v8.5.5","v8.5.6","v8.5.7","v8.5.8","v8.5.9","v8.6.0","v8.6.1","v8.6.10","v8.6.11","v8.6.12","v8.6.2","v8.6.3","v8.6.4","v8.6.5","v8.6.6","v8.6.7","v8.6.8","v8.6.9","v9.0.0","v9.0.1","v9.1.0","v9.1.1","v9.1.2","v9.1.3","v9.1.4","v9.1.5","v9.1.6","v9.1.7","v9.1.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-vv7q-mfpc-qgm5/GHSA-vv7q-mfpc-qgm5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}