Back to Security Advisories
Critical 2026-08-07

EasyApache 4 25.74 — cPanel & WHM Update

cPanel

Security Hotfix We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4. This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular expressions (CVE-2026-42533) that could allow remote code execution or a worker proce…

Affected Versions

25.74

Security Hotfix We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4. This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular expressions (CVE-2026-42533) that could allow remote code execution or a worker proce…

EasyApache 4 25.74

2026 July 16

Security Hotfix

We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4.

This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular expressions (CVE-2026-42533) that could allow remote code execution or a worker process denial of service, plus a memory disclosure in the slice module (CVE-2026-60005) and a use-after-free in the SSI module (CVE-2026-56434). The ea-nginx module packages (ea-nginx-echo, ea-nginx-headers-more, ea-nginx-njs, ea-nginx-passenger, and ea-modsec30-connector-nginx) rebuild against the new nginx.

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System