In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Conclusion & alert: CVE-2019-11043 is rated Critical Active Threat (94.8/100): CVSS High severity, with high exploitation likelihood (EPSS 94.05%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-03-25) affecting PHP / FastCGI Process Manager (FPM). a weakness (CWE-120) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability · CISA KEV detail
: 2022-03-25
: 2022-04-15
: Apply updates per vendor instructions.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 48182 | exploit_db | edb | 2020-03-09 | Exploit-DB ↗ |
| 47553 | exploit_db | edb | 2019-10-28 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-23 | 94.04% | 94.05% | +0.01% |
| 2 | 2026-03-21 | 94.11% | 94.04% | -0.07% |
| 3 | 2025-11-21 | — | 94.11% | — |
Full EPSS history (23 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 3.1 | HIGH |
|
2.2 | 5.8 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2019-11043: 1 source package rows (php7); 1 state rows across 1 repos (edge-community); fixed 1, open 0. | https://security.alpinelinux.org/vuln/CVE-2019-11043 |
gentoo
|
high | CVE-2019-11043: 1 GLSA(s) (201910-01), 1 atom(s) (dev-lang/php); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2019-11043 |
redhat
|
critical | — | https://access.redhat.com/security/cve/CVE-2019-11043 |
suse
|
medium | CVE-2019-11043 severity moderate: SUSE including 978 source package names (apache2-mod_php5, apache2-mod_php5-5.5.14-109.68.1, …), 2003 product×package rows across 57 product lines (SLES for SAP Applications 11 SP2, SUSE CaaS Platform 4.0, … (57 product lines)): Fixed 1440, Known Not Affected 563. | https://www.suse.com/security/cve/CVE-2019-11043/ |
ubuntu
|
medium | CVE-2019-11043 medium priority: Ubuntu including 4 source packages (php5, php7.0, php7.2, php7.3), 24 status rows across 6 suites (bionic, disco, eoan, trusty, upstream, xenial): DNE 15, released 7, needs-triage 2. | https://ubuntu.com/security/CVE-2019-11043 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| php | php | >= 7.1.0, < 7.1.33 | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* |
| php | php | >= 7.2.0, < 7.2.24 | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* |
| php | php | >= 7.3.0, < 7.3.11 | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 12.04 | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* |
| canonical | ubuntu_linux | 14.04 | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 18.04 | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 19.04 | cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 19.10 | cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 29 | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* |
| fedoraproject | fedora | 30 | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
| tenable | tenable.sc | < 5.19.0 | cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:* |
| redhat | software_collections | 1.0 | cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_desktop | 6.0 | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_desktop | 7.0 | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 7.7 | cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 8.1 | cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 8.2 | cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 8.4 | cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 8.6 | cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 8.8 | cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus_compute_node | 7.7 | cpe:2.3:o:redhat:enterprise_linux_eus_compute_node:7.7:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64 | 8.0_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64_eus | 8.1_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.1_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64_eus | 8.2_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.2_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64_eus | 8.4_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.4_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64_eus | 8.6_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.6_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64_eus | 8.8_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.8_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 6.0_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 7.0_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 8.0_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 7.7_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:7.7_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.1_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.1_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.2_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.2_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.4_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.6_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.6_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.8_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.8_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_big_endian | 6.0_ppc64 | cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0_ppc64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_big_endian | 7.0_ppc64 | cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0_ppc64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.7_ppc64 | cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.7_ppc64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian | 7.0_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian | 8.0_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian_eus | 7.7_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:7.7_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.1_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.2_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.4_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.6_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.8_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.8_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_scientific_computing | 7.0 | cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server | 6.0 | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server | 7.0 | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 7.7 | cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 8.2 | cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 8.4 | cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 8.6 | cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_tus | 7.7 | cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_tus | 8.2 | cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_tus | 8.4 | cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_tus | 8.6 | cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_tus | 8.8 | cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:* |
| redhat | enterprise_linux_workstation | 6.0 | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_workstation | 7.0 | cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:* |