In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenable security Center
|
|
| CPEs | cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tenable securitycenter
|
Tenable security Center
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-17T01:47:06.457Z
Reserved: 2019-04-09T00:00:00.000Z
Link: CVE-2019-11044
No data.
Status : Modified
Published: 2019-12-23T03:15:10.913
Modified: 2026-08-17T14:50:49.470
Link: CVE-2019-11044
OpenCVE Enrichment
No data.