---
title: "CVE-2019-11043 - PHP FPM Security Announcement"
date: "2025-02-05T22:51:34+00:00"
summary: "Acquia Cloud is not affected by CVE-2019-11043 PHP FPM vulnerability. Learn why and how your applications stay secure."
image:
type: "article"
url: "/acquia-cloud-platform/help/92221-cve-2019-11043-php-fpm-security-announcement"
id: "bc282b9c-0946-4831-96b7-41eebb818933"
---

PHP.net recently announced a security vulnerability for PHP FPM, [CVE-2019-11043](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11043): 

> In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

The Acquia Security Team has reviewed the details of this vulnerability internally and can confirm that applications on the Acquia Cloud platform are not impacted. This vulnerability exists only in specific Nginx configuration conditions, which are not implemented by Acquia.

Please contact Acquia Support if you have any additional questions and we’ll be happy to assist further.