CVE Tools

CVE-2019-9020

Published: Feb 22, 2019Updated: Nov 21, 2024 Sources: CVE List NVD BDU csafCWE-125

Description

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.

In plain language

AI Worth attention

CVE-2019-9020 is a serious bug in older PHP versions that can crash or potentially let an attacker take control through malformed XML-RPC data; if your small business still runs an affected PHP version, you should act now.

Executive summary

CVE-2019-9020 is a memory-safety issue (CWE-125/CWE-416) in PHP’s xmlrpc_decode() path for ext/xmlrpc, where carefully crafted XML-RPC input can trigger invalid memory access (e.g., heap out-of-bounds read or read-after-free), making remote impact possible in vulnerable deployments; public exploits exist and the likelihood is rising.

If affected, business impact
Service crash (denial of service)Potential PHP process compromiseData exposure from memory readsBusiness disruption for web apps

What to do now

  1. Check whether your server/app runs PHP and which exact version (and whether the xmlrpc extension/functionality is enabled).
  2. If your PHP version is older than the fixes listed below, schedule an upgrade as soon as possible.
  3. Upgrade PHP to a fixed version: 5.6.40 or later, 7.1.26 or later, 7.2.14 or later, or 7.3.1 or later (as applicable to your branch).
  4. Re-test your application’s XML-RPC usage (or disable XML-RPC if you don’t need it) after the upgrade.
  5. If you can’t upgrade immediately, temporarily remove/disable xmlrpc functionality and block external access to any XML-RPC endpoints until the fix is applied.
sudo apt-get update && sudo apt-get install --only-upgrade php
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 4 more affected products View all →

Exploitability

2 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

3 techniques
Collection
Initial Access
Privilege Escalation
View detailed technique mapping

References

and 456 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2019-9020 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store