Zurück zu den Sicherheitshinweisen

EasyApache 4 25.80 — cPanel & WHM Update

EasyApache 4 release 25.80 updates ea-nginx to v1.31.4 and fixes two security issues: a denial of service in the Apache Tomcat WebSocket chat example (CVE-2026-66299) and a CRLF injection in multipart header parsing (CVE-2026-26962), plus a use-after-free in the Redis TLS pending-data list. Servers using EasyApache 4 should update their packages to pick up the fixes.

High 5.3 CVSS
cPanel

Betroffene Versionen

25.80

Was das unter einer SharedLicense-Lizenz bedeutet

The Tomcat flaw (CVE-2026-66299, CWE-400) is a denial of service and the multipart header flaw (CVE-2026-26962) is a CRLF injection — both reachable through requests against the affected components.

EasyApache 4 25.80

2026 August 26

Maintenance and security updates

We released updated packages for EasyApache 4.

This release updates ea-nginx to v1.31.4, which adds PROXY protocol version 2 support to the stream and mail modules, sends the “:authority” pseudo-header on HTTP/2 and gRPC requests to backends, and fixes a worker-process segmentation fault with the select method. The nginx module packages (ea-nginx-echo, ea-nginx-headers-more, ea-nginx-njs, ea-nginx-passenger, and ea-modsec30-connector-nginx) were rebuilt against v1.31.4.

This release also addresses a denial of service in the Apache Tomcat WebSocket chat example (CVE-2026-66299), a use-after-free in the Redis TLS pending-data list, and a CRLF injection in multipart header parsing (CVE-2026-26962). In addition, ea-nginx now builds against PCRE2 on Debian so nginx and its modules resolve the same PCRE library.

For a full list of changes, read the EasyApache 4 change log.

Häufig gestellte Fragen

What does EasyApache 4 25.80 fix?
It fixes a denial of service in the Apache Tomcat WebSocket chat example (CVE-2026-66299), a CRLF injection in multipart header parsing (CVE-2026-26962), and a use-after-free in the Redis TLS pending-data list. It also updates ea-nginx to v1.31.4 with PROXY protocol v2 support and rebuilds the nginx module packages.
Which versions are affected by CVE-2026-66299 and CVE-2026-26962?
Earlier EasyApache 4 package builds shipping the affected Tomcat example and multipart parsing code. Release 25.80 (August 26, 2026) and later contain the fixes; 25.80 is the marker release.
How do I update EasyApache 4?
Run yum update 'ea-*' or use WHM → EasyApache 4 → Update, then confirm the package versions in WHM show 25.80 or later.
Is any action needed beyond updating EasyApache?
No — the fixes ship in the EasyApache 4 packages themselves. Deployments using Apache Tomcat's WebSocket chat example or Redis TLS should independently confirm they are current, since these CVEs originate upstream of cPanel.

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen