Volver a los avisos de seguridad

EasyApache 4 25.74 — cPanel & WHM Update

Critical
cPanel

Versiones afectadas

25.74

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Apply it on every affected server: sudo /scripts/upcp --force. Licenses keep working through updates; nothing needs re-issuing or re-activating.

Security Hotfix We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4. This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular expressions (CVE-2026-42533) that could allow remote code execution or a worker proce…

EasyApache 4 25.74

2026 July 16

Security Hotfix

We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4.

This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular expressions (CVE-2026-42533) that could allow remote code execution or a worker process denial of service, plus a memory disclosure in the slice module (CVE-2026-60005) and a use-after-free in the SSI module (CVE-2026-56434). The ea-nginx module packages (ea-nginx-echo, ea-nginx-headers-more, ea-nginx-njs, ea-nginx-passenger, and ea-modsec30-connector-nginx) rebuild against the new nginx.

For a full list of changes, read the EasyApache 4 change log.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema