Zurück zu den Sicherheitshinweisen

Security: CVE-2026-9256 ea-nginx v1.31.1 Security Release – May 22, 2026

Security vulnerabilities tied to the ea-nginx ngx_http_rewrite_module (CVE-2026-9256) have been discovered.

Critical 8.1 CVSS
CloudLinux cPanel

Betroffene Versionen

31.1

Standard-Update-Befehl

yum update ea-nginx   # or WHM → EasyApache 4 → Update

Was das unter einer SharedLicense-Lizenz bedeutet

Your SharedLicense license itself is not affected — this is a vulnerability in CloudLinux, cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell CloudLinux, cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

Security vulnerabilities tied to the ea-nginx ngx_http_rewrite_module (CVE-2026-9256) have been discovered.

Impact

We are releasing a security update to update ea-nginx to version 1.31.1 to address these vulnerabilities.

Note: Please see the latest EasyApache4 changelogs for version information:
https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ 

Update: EA-nginx v1.31.1 has been released.

2026 May 22
ea-nginx

   EA-13448: Update ea-nginx from v1.31.0 to v1.31.1.
   (CVE-2026-9256) Security: Remote code execution via worker process memory pool handling (nginx-poolslip).

ea-nginx-passenger

   EA-13443: Update ea-nginx-passenger from v6.1.2 to v6.1.3.
 

Call to Action

You can confirm if ea-nginx is installed and updated to the latest version with the following commands:

CloudLinux / AlmaLinux

# dnf list installed ea-nginx

If ea-nginx is installed, but not updated, you can use the following command to proceed with that update:

# dnf update

Ubuntu

# apt policy ea-niginx

If they are installed, there will be a specified version in the “Installed” field, as shown below:

CONFIG_TEXT: # apt policy ea-nginx
ea-nginx:
 Installed: 1.31.0-1+3.2.cpanel
 Candidate: 1.31.0-1+3.2.cpanel

If the Installed field shows “(none)” the package is not installed.

If ea-nginx is installed, but is not updated, you can use the following command to perform the update and upgrade:

# apt update && apt upgrade

Häufig gestellte Fragen

What is CVE-2026-9256?
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Is CVE-2026-9256 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 10.86% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-9256?
Update CloudLinux, cPanel to the patched release.Then confirm the running version matches the patched release listed above.

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen