CVE-2024-11235

Reference counting in php_request_shutdown causes Use-After-Free

In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution.


We have discovered 128,163 live websites that are affected by CVE-2024-11235.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains128,163 live websites (1.76% of PHP install base)
Vulnerable Versions
  • from 8.3 through 8.3.19
  • from 8.4 through 8.4.5
Vulnerable Versions Count24 versions ( 4.68% of all versions)


Common Weakness Enumeration

CWE-416 Use After Free



Details

  • Published - Apr 4, 2025
  • Updated - Feb 26, 2026

Credits

  • Junwha Hong (reporter)

Website Distribution by Country

Number of websites using CVE-2024-11235
United States19,846 websites



France58,508 websites
Brazil4,754 websites
Russia4,315 websites
Germany4,301 websites
Cyprus3,027 websites
Poland2,981 websites
GB2,348 websites
Italy2,300 websites
Netherlands2,243 websites

Website Distribution by TLD

Number of websites using CVE-2024-11235
.com47,646 websites
.fr24,531 websites
.org6,074 websites
.com.br4,097 websites
.ru4,068 websites
.net4,039 websites
.be3,140 websites
.pl2,915 websites
.it2,350 websites
.de2,091 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-11235

Top websites that are affected by CVE-2024-11235. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United States*,***
*******.com Germany*,***
******.com United States*,***
*******.com United States*,***
*****.com United States*,***
*******************.com United States*,***
************.com United States*,***
******************.com Singapore*,***
************.jp Japan*,***
**********.com United States**,***
See full domain list

FAQ

CVE-2024-11235 is Use After Free in PHP
A total of 128,163 websites have been identified as vulnerable to CVE-2024-11235, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2024-11235 vulnerability.
PHP versions up to 8.4.5 are vulnerable to CVE-2024-11235.
CVE-2024-11235 is resolved in version 8.4.5 of PHP.