Back to Security Advisories
High 2026-08-06

Security Advisory: CloudLinux $HTTP_HOST Environment Injection

CloudLinux CloudLinux 7 CloudLinux 9

A vulnerability in CloudLinux LVE Manager allowed environment variable injection via the $HTTP_HOST header, potentially leading to unauthorized access to protected resources.

Affected Versions

7.4 and earlier

Patched Version

7.5

Default Update CMD

yum update -y

Fix Commands

CloudLinux 7

yum clean all
yum update cl-lve

CloudLinux 9

dnf clean metadata
dnf update cl-lve

A vulnerability in CloudLinux LVE Manager allowed environment variable injection via the $HTTP_HOST header, potentially leading to unauthorized access to protected resources.

More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System