Вернуться к предупреждениям о безопасности

Security: CVE-2026-58047 HTTP Request Smuggling

A vulnerability in the cPanel web server allows manipulation of cpsrvd responses under limited conditions.

Critical 5.6 CVSS
cPanel

Команда обновления по умолчанию

sudo /scripts/upcp --force

Что это значит по лицензии SharedLicense

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

A vulnerability in the cPanel web server allows manipulation of cpsrvd responses under limited conditions.

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions 11.110.0.137
11.118.0.71
11.126.0.78
11.134.0.48
11.136.0.32
138.1.6 ( WP2 )

Impact

In some situations, an unauthenticated remote attacker may be able to manipulate responses delivered to other users on the same server. 

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

Mitigation

Servers that cannot immediately upgrade can disable cpsrvd backend connection reuse as a temporary workaround. To do so, run the following commands as the root user:

# echo ‘cpsrvd_keepalives_disabled=1’ >> /var/cpanel/cpanel.config 
# pkill -9 cpsrvd
# /usr/local/cpanel/scripts/restartsrv_cpsrvd

Note: This forces a new TCP+TLS connection per request on ports 2083, 2087, and 2096, which increases latency and CPU usage on busy servers. Make sure to revert this change after upgrading by setting the value to 0 and restarting cpsrvd.

To revert that change, run the following commands as the root user:

# sed -i ‘s/cpsrvd_keepalives_disabled=1/cpsrvd_keepalives_disabled=0/’ /var/cpanel/cpanel.config
# pkill -9 cpsrvd
# /usr/local/cpanel/scripts/restartsrv_cpsrvd

Acknowledgements

WebPros thanks Vincent55 Yang for responsibly disclosing this issue.

Часто задаваемые вопросы

What is CVE-2026-58047?
HTTP Smuggling in cPanel allows potential leak of credentials.
Is CVE-2026-58047 being exploited in the wild?
No confirmed exploitation has been announced. Patch on your normal schedule and watch the vendor advisory for updates.
How do I fix CVE-2026-58047?
Update cPanel to the patched release.Then confirm the running version matches the patched release listed above.

Проверьте систему на уязвимости

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Проверьте свою систему