CVE-2019-11043
Underflow in PHP-FPM can lead to RCE
- Published
- Oct 28, 2019
- Updated
- Oct 21, 2025
- Assigning CNA
- php
- Evidence observed
- Oct 28, 2019
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Sources
28- CVE-2019-11043Exploit
CVE-2019-11043 PHP7.x RCE
- ctf-cve-2019-11043Research
Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment, post-exploitation exercises, and integration with phuip-fpizdam.
- CVE-2019-11043Exploit
CVE-2019–11043: PHP-FPM Nginx Remote Code Execution Vulnerability
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.