Back to Security Advisories

EasyApache 4 25.81 — cPanel & WHM Update

EasyApache 4 release 25.81 patches ea-openssl11 on CentOS 7 against two OpenSSL flaws: a heap buffer overflow in CMS key unwrapping (CVE-2026-63072, CWE-787, CVSS 7.5) and excessive memory use when buffering DTLS records (CVE-2026-54874). CentOS 7 servers using the ea-openssl11 package should update as a priority.

High 7.5 CVSS
cPanel CentOS 7

Affected Versions

25.81

What this means under a SharedLicense license

A heap buffer overflow in CMS key unwrapping is the kind of memory-corruption flaw that can crash or potentially compromise processes using OpenSSL for CMS operations.

EasyApache 4 25.81

2026 September 2

Maintenance and security updates

We released updated packages for EasyApache 4.

This release patches ea-openssl11 on CentOS 7 for a heap buffer overflow in CMS key unwrapping (CVE-2026-63072) and excessive memory use when buffering DTLS records (CVE-2026-54874). It also updates ea-re2c to v4.6 and fixes three ea-podman issues: container hostnames longer than 64 bytes, systemd restart defaults for container units, and modifyacct calls being refused on accounts that own containers.

For a full list of changes, read the EasyApache 4 change log.

Frequently Asked Questions

What is CVE-2026-63072?
It is a heap buffer overflow in OpenSSL's CMS key unwrapping code (CWE-787), rated CVSS 7.5. cPanel ships the fix in the ea-openssl11 package for CentOS 7 in EasyApache 4 release 25.81 (September 2, 2026).
What is CVE-2026-54874?
It is an excessive memory use flaw when OpenSSL buffers DTLS records, fixed in the same ea-openssl11 update — relevant to servers terminating DTLS traffic.
Who needs this update?
CentOS 7 servers running EasyApache 4 with the ea-openssl11 package. Release 25.81 also updates ea-re2c to v4.6 and fixes three ea-podman issues, so a package refresh covers all of it.
How do I apply the fix?
Update the EasyApache 4 packages: yum update 'ea-*' or WHM → EasyApache 4 → Update, and verify the ea-openssl11 package version afterwards.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System