Back to Security Advisories
High 2026-08-07

EasyApache 4 25.67 — cPanel & WHM Update

cPanel

Security updates We released updated packages for EasyApache 4. This security release updates ea-nginx from v1.31.1 to v1.31.2, addressing two CVEs from the nginx 2026-06-17 advisory: CVE-2026-42055 (Medium: buffer overflow in ngx_http_proxy_v2_module and ngx_http_grpc_module) and CVE-2026-48142 (Low: buffer over-re…

Affected Versions

25.67

Security updates We released updated packages for EasyApache 4. This security release updates ea-nginx from v1.31.1 to v1.31.2, addressing two CVEs from the nginx 2026-06-17 advisory: CVE-2026-42055 (Medium: buffer overflow in ngx_http_proxy_v2_module and ngx_http_grpc_module) and CVE-2026-48142 (Low: buffer over-re…

EasyApache 4 25.67

2026 June 18

Security updates

We released updated packages for EasyApache 4.

This security release updates ea-nginx from v1.31.1 to v1.31.2, addressing two CVEs from the nginx 2026-06-17 advisory: CVE-2026-42055 (Medium: buffer overflow in ngx_http_proxy_v2_module and ngx_http_grpc_module) and CVE-2026-48142 (Low: buffer over-read in ngx_http_charset_module). The associated nginx module packages (ea-nginx-echo, ea-nginx-headers-more, ea-nginx-njs, ea-nginx-passenger, ea-modsec30-connector-nginx) were also rebuilt against the patched version. It also updates ea-nodejs22 from v22.22.3 to v22.23.0, the Node.js June 2026 security release addressing 11 CVEs including two High-severity issues (CVE-2026-48618: TLS wildcard auth bypass; CVE-2026-48933: WebCrypto AES integer overflow crash).

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System