EasyApache 4 25.83 — cPanel & WHM Update
EasyApache 4 release 25.83 updates ea-nginx to 1.31.6, which includes the upstream fix for CVE-2026-90439 — a buffer overflow (CWE-122, CVSS 6.5) in nginx's ngx_http_v3_module. cPanel notes that EasyApache 4 does not build that module, so EasyApache 4 installations are not affected; the update is still worthwhile for the PHP and podman refreshes that ride along.
Затронутые версии
25.83
Что это значит по лицензии SharedLicense
The flaw is a buffer overflow in the HTTP/3 module, but because cPanel does not compile ngx_http_v3_module, EasyApache 4 servers have no direct exposure through this package set.
EasyApache 4 25.83
2026 September 16
Security and maintenance updates
We released updated packages for EasyApache 4.
This release updates ea-nginx to 1.31.6, which includes the upstream fix for CVE-2026-90439, a
buffer overflow in the ngx_http_v3_module module. EasyApache 4 does not build that module, so
EasyApache 4 installations are not affected. It also rebuilds the nginx modules, updates
ea-php84 to 8.4.25 and ea-php85 to 8.5.10, and updates ea-podman.
For a full list of changes, read the EasyApache 4 change log.
Часто задаваемые вопросы
What is CVE-2026-90439?
Are EasyApache 4 servers affected by CVE-2026-90439?
Why should I still update to 25.83?
Who IS affected by CVE-2026-90439?
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему