CVE-2019-11049 (matched: php)

  • Wednesday, 19th August, 2026
  • 10:06am

A security issue has been identified in specific versions of PHP, the software many websites use to power features like contact forms and email sending. The affected versions are all PHP 7.3 releases older than 7.3.13, and PHP 7.4.0, when running on Windows servers. The bug occurs when a site uses PHP's built-in mail() function to send emails with custom headers that are written in lowercase. Due to a coding error in these PHP versions, this triggers a double-free of specific memory locations, a type of memory corruption flaw.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2019-11049

« Back