Вернуться к предупреждениям о безопасности

EasyApache 4 25.80 — cPanel & WHM Update

EasyApache 4 release 25.80 updates ea-nginx to v1.31.4 and fixes two security issues: a denial of service in the Apache Tomcat WebSocket chat example (CVE-2026-66299) and a CRLF injection in multipart header parsing (CVE-2026-26962), plus a use-after-free in the Redis TLS pending-data list. Servers using EasyApache 4 should update their packages to pick up the fixes.

High 5.3 CVSS
cPanel

Затронутые версии

25.80

Что это значит по лицензии SharedLicense

The Tomcat flaw (CVE-2026-66299, CWE-400) is a denial of service and the multipart header flaw (CVE-2026-26962) is a CRLF injection — both reachable through requests against the affected components.

EasyApache 4 25.80

2026 August 26

Maintenance and security updates

We released updated packages for EasyApache 4.

This release updates ea-nginx to v1.31.4, which adds PROXY protocol version 2 support to the stream and mail modules, sends the “:authority” pseudo-header on HTTP/2 and gRPC requests to backends, and fixes a worker-process segmentation fault with the select method. The nginx module packages (ea-nginx-echo, ea-nginx-headers-more, ea-nginx-njs, ea-nginx-passenger, and ea-modsec30-connector-nginx) were rebuilt against v1.31.4.

This release also addresses a denial of service in the Apache Tomcat WebSocket chat example (CVE-2026-66299), a use-after-free in the Redis TLS pending-data list, and a CRLF injection in multipart header parsing (CVE-2026-26962). In addition, ea-nginx now builds against PCRE2 on Debian so nginx and its modules resolve the same PCRE library.

For a full list of changes, read the EasyApache 4 change log.

Часто задаваемые вопросы

What does EasyApache 4 25.80 fix?
It fixes a denial of service in the Apache Tomcat WebSocket chat example (CVE-2026-66299), a CRLF injection in multipart header parsing (CVE-2026-26962), and a use-after-free in the Redis TLS pending-data list. It also updates ea-nginx to v1.31.4 with PROXY protocol v2 support and rebuilds the nginx module packages.
Which versions are affected by CVE-2026-66299 and CVE-2026-26962?
Earlier EasyApache 4 package builds shipping the affected Tomcat example and multipart parsing code. Release 25.80 (August 26, 2026) and later contain the fixes; 25.80 is the marker release.
How do I update EasyApache 4?
Run yum update 'ea-*' or use WHM → EasyApache 4 → Update, then confirm the package versions in WHM show 25.80 or later.
Is any action needed beyond updating EasyApache?
No — the fixes ship in the EasyApache 4 packages themselves. Deployments using Apache Tomcat's WebSocket chat example or Redis TLS should independently confirm they are current, since these CVEs originate upstream of cPanel.

Проверьте систему на уязвимости

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Проверьте свою систему