EasyApache4 v25.77 Maintenance and Security Release
PinnedWebPros has released an update for EasyApache 4! Take a look at some highlights below, and then join us on the cPanel Community Forums, Discord, or Reddit to talk about this update and much more. If you have additional questions, feel free to reach out on one of our social channels.
-
ea-php82
-
EA-13519: Update ea-php82 from v8.2.32 to v8.2.33
-
Fixed libgd vulnerability. (CVE-2026-9672; severity not yet assigned)
-
Fixed SQL injection via E'...' backslash breakout. (CVE-2026-17543; High, CVSS 4.0 8.1)
-
Fixed crash via recursive symlinks in Phar archives. (CVE-2026-7260; Medium, CVSS 4.0 5.4)
-
ea-php83
-
EA-13521: Update ea-php83 from v8.3.32 to v8.3.33
-
Fixed libgd vulnerability. (CVE-2026-9672; severity not yet assigned)
-
Fixed SQL injection via E'...' backslash breakout. (CVE-2026-17543; High, CVSS 4.0 8.1)
-
Fixed crash via recursive symlinks in Phar archives. (CVE-2026-7260; Medium, CVSS 4.0 5.4)
-
ea-php84
-
EA-13522: Update ea-php84 from v8.4.23 to v8.4.24
-
Fixed libgd vulnerability. (CVE-2026-9672; severity not yet assigned)
-
Fixed SQL injection via E'...' backslash breakout. (CVE-2026-17543; High, CVSS 4.0 8.1)
-
Fixed crash via recursive symlinks in Phar archives. (CVE-2026-7260; Medium, CVSS 4.0 5.4)
-
Fixed out-of-bounds write in bccomp(). (CVE-2026-17544; High, CVSS 4.0 8.1)
-
ea-php85
-
EA-13520: Update ea-php85 from v8.5.8 to v8.5.9
-
Fixed libgd vulnerability. (CVE-2026-9672; severity not yet assigned)
-
Fixed SQL injection via E'...' backslash breakout. (CVE-2026-17543; High, CVSS 4.0 8.1)
-
Fixed crash via recursive symlinks in Phar archives. (CVE-2026-7260; Medium, CVSS 4.0 5.4)
-
Fixed out-of-bounds write in bccomp(). (CVE-2026-17544; High, CVSS 4.0 8.1)
-
ea-nginx
-
EA-13513: Speed up config rebuilds significantly for users with thousands of domains.
-
ea-nodejs22
-
EA-13518: Update ea-nodejs22 from v22.23.1 to v22.23.2 (upstream Security Release)
-
Fixed http2 header memory retention in session accounting. (CVE-2026-56846; High)
-
Fixed http2 rst stream deferral while in scope. (CVE-2026-56848; High)
-
Fixed permission model granting radix split nodes. (CVE-2026-58043; High)
-
Fixed https PFX object-array agent key distinction. (CVE-2026-56850; Medium)
-
Fixed https identity checks binding to session reuse. (CVE-2026-58040; Medium)
-
Fixed dns handling of large resolveAny address replies. (CVE-2026-58042; Medium)
-
Fixed zlib out-of-bounds write buffers. (CVE-2026-58045; Medium)
-
Fixed permission model fs write permission enforcement for trace events. (CVE-2026-56847; Low)
-
Fixed permission model final report output path check. (CVE-2026-58039; Low)
-
Fixed http max header count enforcement. (CVE-2026-58044; Low)
-
ea-nghttp2
-
EA-13517: Update ea-nghttp2 from v1.69.0 to v1.70.0
-
Fixed base64 out-of-bounds read (upstream #2768; no CVE assigned)
Post is closed for comments.
Comments
0 comments