AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-11049

MEDIUM · CVSS 6.5 EPSS 4.22%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-12-23 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Windows.

CVE
CVE-2019-11049
Severity
MEDIUM
CVSS
6.5
EPSS
4.22%
Windows

Original NVD Description

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.

Related CVEs

Other vulnerabilities affecting the same vendor(s)