CVE-2024-11235: PHP

High severity, CVSS 8.1. EPSS: 1.5% chance of exploitation in the next 30 days.

In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution.

Affected products

  • PHP PHP: from 8.3.0, before 8.3.19 (fixed in 8.3.19); from 8.4.0, before 8.4.5 (fixed in 8.4.5)

Published 2025-04-04. Last modified 2026-06-17.