{"id":"CVE-2019-11043","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-11043","summary":null,"details":"In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.","published":"2019-10-28T15:15:13.863Z","modified":"2026-08-07T11:31:24.278690274Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.9978,"percentile":0.99955,"asOf":"2026-08-27"},"cisaKev":{"dateAdded":"2022-03-25","dueDate":"2022-04-15","knownRansomwareCampaignUse":true},"exploitsKnown":36,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11043"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2020/Jan/40"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3286"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3287"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3299"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3300"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3724"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3735"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3736"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0322"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2020/Jan/44"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20191031-0003/"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210919"},{"type":"ADVISORY","url":"https://support.f5.com/csp/article/K75408500?utm_source=f5support&amp%3Butm_medium=RSS"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4166-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4166-2/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4552"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4553"},{"type":"ADVISORY","url":"https://www.synology.com/security/advisory/Synology_SA_19_36"},{"type":"ADVISORY","url":"https://www.tenable.com/security/tns-2021-14"},{"type":"FIX","url":"https://bugs.php.net/bug.php?id=78599"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"https://github.com/neex/phuip-fpizdam"}],"provenance":{"sources":["OSV.dev","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:24.278690274Z"}}