CVE-2019-11049 (matched: php)

  • Wednesday, 19th August, 2026
  • 16:05pm

A security flaw has been identified in specific versions of PHP, the programming language that powers many dynamic websites. The issue only affects PHP 7.3.x versions older than 7.3.13, and PHP 7.4.0, and only when these versions are running on Windows servers. The flaw is triggered when a site uses PHP’s built-in mail() function to send emails, and passes custom email headers written in lowercase. This error causes a dangerous memory malfunction that attackers could potentially exploit to gain unauthorized access to a site, run malicious code, or disrupt normal site operation. If your site runs a different PHP version, or runs on a non-Windows server, it is not impacted by this flaw.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2019-11049

« Back