CVE-2019-11043: listed in the CISA KEV catalog CVE-2019-11043 · CVSS 8.7 HIGH · EPSS 99.8% · KEV 2022-03-25 · patch available
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Is CVE-2019-11043 exploited? Listed in the CISA KEV catalog on 2022-03-25. Federal remediation due 2022-04-15. Past that date by 1595 days. Used in ransomware campaigns. EPSS puts exploitation in the next 30 days at 99.8%. Which products and versions are affected? PHP · PHP · >= 7.1.x, < 7.1.33, >= 7.2.x, < 7.2.24, >= 7.3.x, < 7.3.11 canonical · ubuntu linux · 12.04, 14.04, 16.04, 18.04, 19.04, 19.10 debian · debian linux · 9.0, 10.0 fedoraproject · fedora · 29, 30, 31 tenable · tenable.sc · < 5.19.0 redhat · software collections · 1.0 redhat · enterprise linux · 8.0 redhat · enterprise linux desktop · 6.0, 7.0 redhat · enterprise linux eus · 7.7, 8.1, 8.2, 8.4, 8.6, 8.8 redhat · enterprise linux eus compute node · 7.7 redhat · enterprise linux for arm 64 · 8.0_aarch64 redhat · enterprise linux for arm 64 eus · 8.1_aarch64, 8.2_aarch64, 8.4_aarch64, 8.6_aarch64, 8.8_aarch64 redhat · enterprise linux for ibm z systems · 6.0_s390x, 7.0_s390x, 8.0_s390x redhat · enterprise linux for ibm z systems eus · 7.7_s390x, 8.1_s390x, 8.2_s390x, 8.4_s390x, 8.6_s390x, 8.8_s390x redhat · enterprise linux for power big endian · 6.0_ppc64, 7.0_ppc64 redhat · enterprise linux for power big endian eus · 7.7_ppc64 redhat · enterprise linux for power little endian · 7.0_ppc64le, 8.0_ppc64le redhat · enterprise linux for power little endian eus · 7.7_ppc64le, 8.1_ppc64le, 8.2_ppc64le, 8.4_ppc64le, 8.6_ppc64le, 8.8_ppc64le redhat · enterprise linux for scientific computing · 7.0 redhat · enterprise linux server · 6.0, 7.0 Is there a patch? What PlainSec published about CVE-2019-11043 Primary sources What this record does not say KEV and EPSS are re-checked daily. Record last updated 2026-08-27.
CVE-2019-11043: listed in the CISA KEV catalog CVE-2019-11043 · CVSS 8.7 HIGH · EPSS 99.8% · KEV 2022-03-25 · patch available
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Is CVE-2019-11043 exploited? Listed in the CISA KEV catalog on 2022-03-25. Federal remediation due 2022-04-15. Past that date by 1595 days. Used in ransomware campaigns. EPSS puts exploitation in the next 30 days at 99.8%. Which products and versions are affected? PHP · PHP · >= 7.1.x, < 7.1.33, >= 7.2.x, < 7.2.24, >= 7.3.x, < 7.3.11 canonical · ubuntu linux · 12.04, 14.04, 16.04, 18.04, 19.04, 19.10 debian · debian linux · 9.0, 10.0 fedoraproject · fedora · 29, 30, 31 tenable · tenable.sc · < 5.19.0 redhat · software collections · 1.0 redhat · enterprise linux · 8.0 redhat · enterprise linux desktop · 6.0, 7.0 redhat · enterprise linux eus · 7.7, 8.1, 8.2, 8.4, 8.6, 8.8 redhat · enterprise linux eus compute node · 7.7 redhat · enterprise linux for arm 64 · 8.0_aarch64 redhat · enterprise linux for arm 64 eus · 8.1_aarch64, 8.2_aarch64, 8.4_aarch64, 8.6_aarch64, 8.8_aarch64 redhat · enterprise linux for ibm z systems · 6.0_s390x, 7.0_s390x, 8.0_s390x redhat · enterprise linux for ibm z systems eus · 7.7_s390x, 8.1_s390x, 8.2_s390x, 8.4_s390x, 8.6_s390x, 8.8_s390x redhat · enterprise linux for power big endian · 6.0_ppc64, 7.0_ppc64 redhat · enterprise linux for power big endian eus · 7.7_ppc64 redhat · enterprise linux for power little endian · 7.0_ppc64le, 8.0_ppc64le redhat · enterprise linux for power little endian eus · 7.7_ppc64le, 8.1_ppc64le, 8.2_ppc64le, 8.4_ppc64le, 8.6_ppc64le, 8.8_ppc64le redhat · enterprise linux for scientific computing · 7.0 redhat · enterprise linux server · 6.0, 7.0 Is there a patch? What PlainSec published about CVE-2019-11043 Primary sources What this record does not say KEV and EPSS are re-checked daily. Record last updated 2026-08-27.