CVE-2019-11049 (matched: php)

  • Tuesday, 18th August, 2026
  • 10:07am

A security vulnerability has been found in specific versions of PHP, the programming language that powers most dynamic websites. This issue impacts PHP 7.3.x versions older than 7.3.13, and PHP 7.4.0, when they are running on Windows servers. The flaw is triggered when a site uses PHP’s built-in mail() function to send emails with custom headers that are written entirely in lowercase letters. The error causes a memory management glitch that attackers could potentially exploit to run unauthorized code or gain access to the server hosting the website. Sites running other PHP versions, or PHP on non-Windows operating systems, are not impacted by this specific flaw.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2019-11049

« Back