Volver a los avisos de seguridad

EasyApache 4 25.83 — cPanel & WHM Update

EasyApache 4 release 25.83 updates ea-nginx to 1.31.6, which includes the upstream fix for CVE-2026-90439 — a buffer overflow (CWE-122, CVSS 6.5) in nginx's ngx_http_v3_module. cPanel notes that EasyApache 4 does not build that module, so EasyApache 4 installations are not affected; the update is still worthwhile for the PHP and podman refreshes that ride along.

High 6.5 CVSS
cPanel

Versiones afectadas

25.83

Lo que esto significa bajo una licencia de SharedLicense

The flaw is a buffer overflow in the HTTP/3 module, but because cPanel does not compile ngx_http_v3_module, EasyApache 4 servers have no direct exposure through this package set.

EasyApache 4 25.83

2026 September 16

Security and maintenance updates

We released updated packages for EasyApache 4.

This release updates ea-nginx to 1.31.6, which includes the upstream fix for CVE-2026-90439, a
buffer overflow in the ngx_http_v3_module module. EasyApache 4 does not build that module, so
EasyApache 4 installations are not affected. It also rebuilds the nginx modules, updates
ea-php84 to 8.4.25 and ea-php85 to 8.5.10, and updates ea-podman.

For a full list of changes, read the EasyApache 4 change log.

Preguntas frecuentes

What is CVE-2026-90439?
It is a buffer overflow in nginx's ngx_http_v3_module (CWE-122, CVSS 6.5), fixed upstream in nginx 1.31.6. EasyApache 4 25.83 ships that updated nginx.
Are EasyApache 4 servers affected by CVE-2026-90439?
No — cPanel states that EasyApache 4 does not build ngx_http_v3_module, so installations are not affected by this specific flaw. The release note exists so operators of stock nginx servers know the upstream fix is available.
Why should I still update to 25.83?
Besides the nginx bump, release 25.83 (September 16, 2026) updates ea-php84 to 8.4.25, ea-php85 to 8.5.10 and ea-podman — routine maintenance that keeps the stack current.
Who IS affected by CVE-2026-90439?
Servers running nginx builds that include the HTTP/3 ngx_http_v3_module below 1.31.6 — for example self-compiled or upstream-distributed nginx with HTTP/3 enabled, rather than EasyApache 4's package set.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema