EasyApache 4 25.82 — cPanel & WHM Update
EasyApache 4 release 25.82 is a security update that bumps ea-libxml2 to 2.15.4, fixing eight libxml2 vulnerabilities (CVE-2026-86137 through CVE-2026-86144), patches two resolv flaws in ea-ruby27-ruby (CVE-2026-80212 and CVE-2026-80213), and updates ea-nginx to 1.31.5. The low aggregate CVSS (2.9) reflects mostly minor issues, but the package refresh is still worth applying.
Affected Versions
25.82
What this means under a SharedLicense license
The libxml2 batch — including an out-of-bounds read (CWE-125) — consists of mostly low-severity parsing flaws, but libxml2 underpins many PHP-facing XML workloads, so exposure is broad even when individual impact is small.
EasyApache 4 25.82
2026 September 9
Security and maintenance updates
We released updated packages for EasyApache 4.
This security release updates ea-libxml2 to 2.15.4, which fixes eight vulnerabilities
(CVE-2026-86137, CVE-2026-86138, CVE-2026-86139, CVE-2026-86140, CVE-2026-86141, CVE-2026-86142,
CVE-2026-86143 and CVE-2026-86144), and patches ea-ruby27-ruby for two vulnerabilities in resolv
(CVE-2026-80212 and CVE-2026-80213). It also updates ea-nginx to 1.31.5 with rebuilds of the
nginx modules, and adds ea-podman compatibility with CageFS 7.6.39.
For a full list of changes, read the EasyApache 4 change log.
Frequently Asked Questions
Which CVEs does EasyApache 4 25.82 fix?
How severe are the libxml2 issues in 25.82?
How do I update?
Does ea-nginx need a separate update?
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System