Skip to main content

PHP security briefs

1 published alerts for PHP products and services.

Actively exploited (KEV)Ransomware

CVE-2019-11043

PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

PHP FastCGI Process Manager (FPM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11043). In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.