EasyApache 4 25.60 — cPanel & WHM Update
Affected Versions
25.60
What this means under a SharedLicense license
Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Apply it on every affected server: sudo /scripts/upcp --force. Licenses keep working through updates; nothing needs re-issuing or re-activating.
Security update We released updated packages for EasyApache 4. This security release addresses CVE-2026-42945 (Critical: heap buffer overflow in ngx_http_rewrite_module) in ea-nginx (v1.30.0 to v1.31.0), along with rebuilds of ea-nginx-echo, ea-nginx-headers-more, ea-nginx-passenger, and ea-nginx-njs against the pat…
EasyApache 4 25.60
2026 May 13
Security update
We released updated packages for EasyApache 4.
This security release addresses CVE-2026-42945 (Critical: heap buffer overflow in ngx_http_rewrite_module) in ea-nginx (v1.30.0 to v1.31.0), along with rebuilds of ea-nginx-echo, ea-nginx-headers-more, ea-nginx-passenger, and ea-nginx-njs against the patched version.
For a full list of changes, read the EasyApache 4 change log.
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System