Back to Security Advisories
Critical 2026-08-07

EasyApache 4 25.60 — cPanel & WHM Update

cPanel

Security update We released updated packages for EasyApache 4. This security release addresses CVE-2026-42945 (Critical: heap buffer overflow in ngx_http_rewrite_module) in ea-nginx (v1.30.0 to v1.31.0), along with rebuilds of ea-nginx-echo, ea-nginx-headers-more, ea-nginx-passenger, and ea-nginx-njs against the pat…

Affected Versions

25.60

Security update We released updated packages for EasyApache 4. This security release addresses CVE-2026-42945 (Critical: heap buffer overflow in ngx_http_rewrite_module) in ea-nginx (v1.30.0 to v1.31.0), along with rebuilds of ea-nginx-echo, ea-nginx-headers-more, ea-nginx-passenger, and ea-nginx-njs against the pat…

EasyApache 4 25.60

2026 May 13

Security update

We released updated packages for EasyApache 4.

This security release addresses CVE-2026-42945 (Critical: heap buffer overflow in ngx_http_rewrite_module) in ea-nginx (v1.30.0 to v1.31.0), along with rebuilds of ea-nginx-echo, ea-nginx-headers-more, ea-nginx-passenger, and ea-nginx-njs against the patched version.

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System