EasyApache 4 25.80 — cPanel & WHM Update
EasyApache 4 release 25.80 updates ea-nginx to v1.31.4 and fixes two security issues: a denial of service in the Apache Tomcat WebSocket chat example (CVE-2026-66299) and a CRLF injection in multipart header parsing (CVE-2026-26962), plus a use-after-free in the Redis TLS pending-data list. Servers using EasyApache 4 should update their packages to pick up the fixes.
Затронутые версии
25.80
Что это значит по лицензии SharedLicense
The Tomcat flaw (CVE-2026-66299, CWE-400) is a denial of service and the multipart header flaw (CVE-2026-26962) is a CRLF injection — both reachable through requests against the affected components.
EasyApache 4 25.80
2026 August 26
Maintenance and security updates
We released updated packages for EasyApache 4.
This release updates ea-nginx to v1.31.4, which adds PROXY protocol version 2 support to the stream and mail modules, sends the “:authority” pseudo-header on HTTP/2 and gRPC requests to backends, and fixes a worker-process segmentation fault with the select method. The nginx module packages (ea-nginx-echo, ea-nginx-headers-more, ea-nginx-njs, ea-nginx-passenger, and ea-modsec30-connector-nginx) were rebuilt against v1.31.4.
This release also addresses a denial of service in the Apache Tomcat WebSocket chat example (CVE-2026-66299), a use-after-free in the Redis TLS pending-data list, and a CRLF injection in multipart header parsing (CVE-2026-26962). In addition, ea-nginx now builds against PCRE2 on Debian so nginx and its modules resolve the same PCRE library.
For a full list of changes, read the EasyApache 4 change log.
Часто задаваемые вопросы
What does EasyApache 4 25.80 fix?
Which versions are affected by CVE-2026-66299 and CVE-2026-26962?
How do I update EasyApache 4?
Is any action needed beyond updating EasyApache?
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему