EasyApache 4 25.67 — cPanel & WHM Update
Security updates We released updated packages for EasyApache 4. This security release updates ea-nginx from v1.31.1 to v1.31.2, addressing two CVEs from the nginx 2026-06-17 advisory: CVE-2026-42055 (Medium: buffer overflow in ngx_http_proxy_v2_module and ngx_http_grpc_module) and CVE-2026-48142 (Low: buffer over-re…
Affected Versions
25.67
Security updates We released updated packages for EasyApache 4. This security release updates ea-nginx from v1.31.1 to v1.31.2, addressing two CVEs from the nginx 2026-06-17 advisory: CVE-2026-42055 (Medium: buffer overflow in ngx_http_proxy_v2_module and ngx_http_grpc_module) and CVE-2026-48142 (Low: buffer over-re…
EasyApache 4 25.67
2026 June 18
Security updates
We released updated packages for EasyApache 4.
This security release updates ea-nginx from v1.31.1 to v1.31.2, addressing two CVEs from the nginx 2026-06-17 advisory: CVE-2026-42055 (Medium: buffer overflow in ngx_http_proxy_v2_module and ngx_http_grpc_module) and CVE-2026-48142 (Low: buffer over-read in ngx_http_charset_module). The associated nginx module packages (ea-nginx-echo, ea-nginx-headers-more, ea-nginx-njs, ea-nginx-passenger, ea-modsec30-connector-nginx) were also rebuilt against the patched version. It also updates ea-nodejs22 from v22.22.3 to v22.23.0, the Node.js June 2026 security release addressing 11 CVEs including two High-severity issues (CVE-2026-48618: TLS wildcard auth bypass; CVE-2026-48933: WebCrypto AES integer overflow crash).
For a full list of changes, read the EasyApache 4 change log.
How to Apply the Fix
Update the affected packages on your server to the patched release, then restart the relevant services.
sudo /scripts/upcp --force
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System