CVE-2019-11043

Underflow in PHP-FPM can lead to RCE

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.


We have discovered 137,319 live websites that are affected by CVE-2019-11043.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains137,319 live websites (1.77% of PHP install base)
Vulnerable Versions
  • from 7.1 through 7.1.33
  • from 7.2 through 7.2.24
  • from 7.3 through 7.3.11
Vulnerable Versions Count68 versions ( 14% of all versions)


Common Weakness Enumeration

CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')



Details

  • Published - Oct 28, 2019
  • Updated - Oct 21, 2025

Credits

  • Reported by Emil Lerner.

Website Distribution by Country

Number of websites using CVE-2019-11043
United States16,946 websites



France52,619 websites
Netherlands9,535 websites
China9,281 websites
Russia7,516 websites
Japan5,790 websites
Germany4,487 websites
Poland2,708 websites
Italy2,028 websites
Spain1,895 websites

Website Distribution by TLD

Number of websites using CVE-2019-11043
.com52,999 websites
.fr21,903 websites
.nl7,014 websites
.ru6,210 websites
.net3,996 websites
.org3,995 websites
.de2,988 websites
.be2,892 websites
.pl2,636 websites
.it1,960 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2019-11043

Top websites that are affected by CVE-2019-11043. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*.cn China*,***
*****.cn China*,***
*********.com China*,***
****.com China*,***
*****.**.com China*,***
*****.org United States*,***
********.com United States*,***
********.com United States**,***
*****.***.tr Turkey**,***
********.com France**,***
See full domain list

FAQ

CVE-2019-11043 is Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in PHP
A total of 137,319 websites have been identified as vulnerable to CVE-2019-11043, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2019-11043 vulnerability.
PHP versions up to 7.3.11 are vulnerable to CVE-2019-11043.
CVE-2019-11043 is resolved in version 7.3.11 of PHP.

References