CVE-2019-11043: listed in the CISA KEV catalog

CVE-2019-11043 · CVSS 8.7 HIGH · EPSS 99.8% · KEV 2022-03-25 · patch available

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

Is CVE-2019-11043 exploited?

Which products and versions are affected?

Is there a patch?

What PlainSec published about CVE-2019-11043

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-27.