Zurück zu den Sicherheitshinweisen

EasyApache 4 25.83 — cPanel & WHM Update

EasyApache 4 release 25.83 updates ea-nginx to 1.31.6, which includes the upstream fix for CVE-2026-90439 — a buffer overflow (CWE-122, CVSS 6.5) in nginx's ngx_http_v3_module. cPanel notes that EasyApache 4 does not build that module, so EasyApache 4 installations are not affected; the update is still worthwhile for the PHP and podman refreshes that ride along.

High 6.5 CVSS
cPanel

Betroffene Versionen

25.83

Was das unter einer SharedLicense-Lizenz bedeutet

The flaw is a buffer overflow in the HTTP/3 module, but because cPanel does not compile ngx_http_v3_module, EasyApache 4 servers have no direct exposure through this package set.

EasyApache 4 25.83

2026 September 16

Security and maintenance updates

We released updated packages for EasyApache 4.

This release updates ea-nginx to 1.31.6, which includes the upstream fix for CVE-2026-90439, a
buffer overflow in the ngx_http_v3_module module. EasyApache 4 does not build that module, so
EasyApache 4 installations are not affected. It also rebuilds the nginx modules, updates
ea-php84 to 8.4.25 and ea-php85 to 8.5.10, and updates ea-podman.

For a full list of changes, read the EasyApache 4 change log.

Häufig gestellte Fragen

What is CVE-2026-90439?
It is a buffer overflow in nginx's ngx_http_v3_module (CWE-122, CVSS 6.5), fixed upstream in nginx 1.31.6. EasyApache 4 25.83 ships that updated nginx.
Are EasyApache 4 servers affected by CVE-2026-90439?
No — cPanel states that EasyApache 4 does not build ngx_http_v3_module, so installations are not affected by this specific flaw. The release note exists so operators of stock nginx servers know the upstream fix is available.
Why should I still update to 25.83?
Besides the nginx bump, release 25.83 (September 16, 2026) updates ea-php84 to 8.4.25, ea-php85 to 8.5.10 and ea-podman — routine maintenance that keeps the stack current.
Who IS affected by CVE-2026-90439?
Servers running nginx builds that include the HTTP/3 ngx_http_v3_module below 1.31.6 — for example self-compiled or upstream-distributed nginx with HTTP/3 enabled, rather than EasyApache 4's package set.

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen