Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-31109

21
FAUCET Score

CVE-2022-31109 affects laminas-diactoros, a PHP package, allowing attackers to manipulate the host, protocol, or port of a URI instance via X-Forwarded-* headers if the application is not behind a trusted proxy. This medium-severity vulnerability (CVSS 6.1) can lead to Cross-Site Scripting (XSS) and URL poisoning, requiring user interaction (UI:R) for exploitation. While the vulnerability has a low EPSS score and no known active exploitation, exploit code, or significant community discussion, users are advised to upgrade to version 2.11.1 or later, or configure web servers to reject X-Forwarded-* headers as a mitigation.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.11.1CPE matchmatch criteria
cpe:2.3:a:getlaminas:laminas-diactoros:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.61%
Probability of exploitation in next 30 days
EPSS Percentile
45.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 49th percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: laminas/laminas-diactorosFixed in: 2.11.1
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-8274-h5jp-97vrmedium

Diactoros before 2.11.1 vulnerable to HTTP Host Header Attack

Jul 27, 2022

References

github.com / laminas/laminas-diactoros/commit/25b11d422c2e5dad868f68619888763b30f91e2d
PatchThird Party Advisory
github.com / laminas/laminas-diactoros/security/advisories/GHSA-8274-h5jp-97vr
MitigationThird Party Advisory
portswigger.net / web-security/host-header
Third Party Advisory