CVE-2019-11049 (matched: php)

  • Tuesday, 18th August, 2026
  • 16:06pm

A security flaw has been found in specific versions of PHP, the software that powers many websites, when it runs on Windows servers. The issue affects PHP 7.3.x versions older than 7.3.13, as well as PHP 7.4.0. It is triggered when your website uses PHP’s built-in mail() function to send emails with custom headers written in lowercase, and is caused by a coding error in the PHP software.

This error leads to memory being freed twice, a type of security flaw that attackers can exploit to gain unauthorized access to your server, run malicious code, or disrupt your website’s normal operation.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2019-11049

« Back