What happened
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
Affected versions
FastCGI Process Manager (FPM): See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 48182PHP-FPM - Underflow Remote Code Execution (Metasploit)Metasploit2020-03-09VerifiedExploit-DB 47553PHP-FPM + Nginx - Remote Code ExecutionEmil Lerner2019-10-28VerifiedSploitusExploit for CVE-2019-11043. CVSS 9.8.Sploitus index2026-09-08T14:40:45+00:00CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.