EasyApache 4 25.74 — cPanel & WHM Update
Security Hotfix We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4. This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular expressions (CVE-2026-42533) that could allow remote code execution or a worker proce…
Affected Versions
25.74
Security Hotfix We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4. This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular expressions (CVE-2026-42533) that could allow remote code execution or a worker proce…
EasyApache 4 25.74
2026 July 16
Security Hotfix
We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4.
This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular expressions (CVE-2026-42533) that could allow remote code execution or a worker process denial of service, plus a memory disclosure in the slice module (CVE-2026-60005) and a use-after-free in the SSI module (CVE-2026-56434). The ea-nginx module packages (ea-nginx-echo, ea-nginx-headers-more, ea-nginx-njs, ea-nginx-passenger, and ea-modsec30-connector-nginx) rebuild against the new nginx.
For a full list of changes, read the EasyApache 4 change log.
How to Apply the Fix
Update the affected packages on your server to the patched release, then restart the relevant services.
sudo /scripts/upcp --force
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System