Zurück zu den Sicherheitshinweisen

EasyApache 4 25.86 — cPanel & WHM Update

EasyApache 4 release 25.86 (September 30, 2026) fixes eleven PHP vulnerabilities by updating ea-php82 to 8.2.34, ea-php83 to 8.3.35, ea-php84 to 8.4.26 and ea-php85 to 8.5.11, and also bumps ea-nodejs22 to 22.23.3 and ea-ruby27-libuv to 1.53.0. The individual issues are mostly low severity (the release's aggregate CVSS is 3.4, including a buffer-overflow class item, CWE-122), but any EasyApache 4 server running PHP should take the package update.

High 3.4 CVSS
cPanel

Betroffene Versionen

25.86

Was das unter einer SharedLicense-Lizenz bedeutet

The fixes close eleven vulnerabilities in the packaged PHP interpreters — memory-corruption and parsing flaws of mostly low severity individually, but PHP runs every hosted site, so unpatched interpreters expose all hosted accounts on the server.

EasyApache 4 25.86

2026 September 30

Security and maintenance updates

We released updated packages for EasyApache 4.

This security release updates ea-php82 to 8.2.34, ea-php83 to 8.3.35, ea-php84 to 8.4.26 and ea-php85 to 8.5.11, which fix eleven vulnerabilities (CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-17545, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842 and CVE-2026-93682). It also updates ea-nodejs22 to 22.23.3 and ea-ruby27-libuv to 1.53.0, and improves ea-podman container upgrades and cleanup.

For a full list of changes, read the EasyApache 4 change log.

Häufig gestellte Fragen

What does EasyApache 4 25.86 fix?
Eleven PHP vulnerabilities (CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-17545, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842 and CVE-2026-93682) via PHP point-release updates to 8.2.34, 8.3.35, 8.4.26 and 8.5.11. It also updates ea-nodejs22 to 22.23.3 and ea-ruby27-libuv to 1.53.0, and improves ea-podman container upgrades and cleanup.
Which EasyApache 4 versions are affected?
Package builds before 25.86. The marker release is 25.86 (September 30, 2026); all four PHP package lines (ea-php82 through ea-php85) received the fixes, so servers running any PHP 8.2–8.5 version on EasyApache 4 should update.
How do I apply the fix?
Run yum update 'ea-*' or use WHM → EasyApache 4 → Update, then confirm the PHP packages show the 25.86-era versions (ea-php84 8.4.26, ea-php85 8.5.11 or later). Per-advisory update commands vary for the individual CVEs, but the package refresh covers all eleven.
Are these PHP flaws severe?
Individually mostly low — the release's aggregate CVSS is 3.4, with a buffer overflow class issue (CWE-122) among them. Low severity does not mean skip: PHP processes untrusted input on every request, and the update also carries Node.js and libuv refreshes.

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen