Вернуться к предупреждениям о безопасности

Security: CVE-2026-9256 ea-nginx v1.31.1 Security Release – May 22, 2026

Security vulnerabilities tied to the ea-nginx ngx_http_rewrite_module (CVE-2026-9256) have been discovered.

Critical 8.1 CVSS
CloudLinux cPanel

Затронутые версии

31.1

Команда обновления по умолчанию

yum update ea-nginx   # or WHM → EasyApache 4 → Update

Что это значит по лицензии SharedLicense

Your SharedLicense license itself is not affected — this is a vulnerability in CloudLinux, cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell CloudLinux, cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

Security vulnerabilities tied to the ea-nginx ngx_http_rewrite_module (CVE-2026-9256) have been discovered.

Impact

We are releasing a security update to update ea-nginx to version 1.31.1 to address these vulnerabilities.

Note: Please see the latest EasyApache4 changelogs for version information:
https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ 

Update: EA-nginx v1.31.1 has been released.

2026 May 22
ea-nginx

   EA-13448: Update ea-nginx from v1.31.0 to v1.31.1.
   (CVE-2026-9256) Security: Remote code execution via worker process memory pool handling (nginx-poolslip).

ea-nginx-passenger

   EA-13443: Update ea-nginx-passenger from v6.1.2 to v6.1.3.
 

Call to Action

You can confirm if ea-nginx is installed and updated to the latest version with the following commands:

CloudLinux / AlmaLinux

# dnf list installed ea-nginx

If ea-nginx is installed, but not updated, you can use the following command to proceed with that update:

# dnf update

Ubuntu

# apt policy ea-niginx

If they are installed, there will be a specified version in the “Installed” field, as shown below:

CONFIG_TEXT: # apt policy ea-nginx
ea-nginx:
 Installed: 1.31.0-1+3.2.cpanel
 Candidate: 1.31.0-1+3.2.cpanel

If the Installed field shows “(none)” the package is not installed.

If ea-nginx is installed, but is not updated, you can use the following command to perform the update and upgrade:

# apt update && apt upgrade

Часто задаваемые вопросы

What is CVE-2026-9256?
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Is CVE-2026-9256 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 10.86% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-9256?
Update CloudLinux, cPanel to the patched release.Then confirm the running version matches the patched release listed above.

Проверьте систему на уязвимости

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Проверьте свою систему