EasyApache4 v25.70 Maintenance and Security Release
WebPros has released an update for EasyApache 4! Take a look at some highlights below, and then join us on the cPanel Community Forums, Discord, or Reddit to talk about this update and much more. If you have additional questions, feel free to reach out on one of our social channels.
-
ea-php82
-
EA-13482: Update ea-php82 from v8.2.31 to v8.2.32
-
Fixed bug GH-22187 (Memory corruption in openssl_encrypt with AES-WRAP-PAD). (CVE-2026-14355)
-
ea-php83
-
EA-13483: Update ea-php83 from v8.3.31 to v8.3.32
-
Fixed bug GH-21468 (TLS setup failure leading to remote DoS). (CVE-2026-12184)
-
Fixed bug GH-22187 (Memory corruption in openssl_encrypt with AES-WRAP-PAD). (CVE-2026-14355)
-
ea-php84
-
EA-13484: Update ea-php84 from v8.4.22 to v8.4.23
-
Fixed bug GH-22187 (Memory corruption in openssl_encrypt with AES-WRAP-PAD). (CVE-2026-14355)
-
ea-php85
-
EA-13485: Update ea-php85 from v8.5.7 to v8.5.8
-
Fixed bug GH-22187 (Memory corruption in openssl_encrypt with AES-WRAP-PAD). (CVE-2026-14355)
-
ea-libcurl
-
EA-13474: Security: backport CVE-2026-8458 (Negotiate connection reuse ignores CURLOPT_SERVICE_NAME, Low)
-
EA-13474: Security: backport CVE-2026-8926 (netrc returns wrong user's password on login mismatch, Low)
-
EA-13474: Security: backport CVE-2026-11586 (WebSocket auto-PONG unbounded memory allocation, Low)
-
EA-13474: Security: backport CVE-2026-11856 (cross-origin Digest auth state leak on handle reuse, Medium)
-
EA-13474: Security: backport CVE-2026-8924 (trailing dot domain super cookie bypass PSL, Low)
-
EA-13474: Security: backport CVE-2026-9079 (stale proxy password on NULL userpwd, Medium)
-
EA-13474: Security: backport CVE-2026-8286 (STARTTLS connection reuse ignores TLS config, Low)
-
EA-13474: Security: backport CVE-2026-9080 (UAF after curl_easy_pause in socket callback, Low)
-
EA-13474: Security: backport CVE-2026-8927 (cross-proxy Digest auth state leak via env proxy, Medium)
-
EA-13474: Security: backport CVE-2026-10536 (HTTP/2 stream-dependency tree UAF, Low)
-
EA-13474: Security: backport CVE-2026-11564 (native CA trust persists after handle reuse, Low)
-
EA-13474: Security: backport CVE-2026-8932 (incomplete mTLS config match in conn reuse, Low)
-
EA-13474: Security: backport CVE-2026-12064 (proto-default skips SSH host verification on schemeless URLs, Low)
Post is closed for comments.
Comments
0 comments