EasyApache 4 25.39 Maintenance Release
Webpros has released an update for EasyApache 4! Take a look at some highlights below, and then join us on the cPanel Community Forums, Discord, or Reddit to talk about this update and much more. If you have additional questions, feel free to reach out on one of our social channels.
-
ea-apache24
-
EA-13281: Update ea-apache24 from v2.4.65 to v2.4.66
-
- low: Apache HTTP Server: mod_md (ACME), unintended retry intervals (CVE-2025-55753)
-
- low: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (CVE-2025-58098)
-
- moderate: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (CVE-2025-59775)
-
- low: Apache HTTP Server: CGI environment variable override (CVE-2025-65082)
-
- moderate: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (CVE-2025-66200)
-
EA-13281: Backport mod_md v2.6.7 fix for MDStapleOthers regression
-
ea-cpanel-tools
-
EA4-213: Add wappspector dep back to avoid it getting removed erroneously
Information about all releases this year can be found in the 2025 EasyApache 4 Changelog.
You can follow our RSS feed for all our releases here: https://docs.cpanel.net/release-notes/release-notes/index.xml
Post is closed for comments.
Comments
0 comments