CVE-2019-14511: Sphinxsearch Sphinx

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).

Affected products

Published 2019-08-22. Last modified 2026-06-17.