EasyApache4 v25.82 Maintenance and Security Release
PinnedWebPros has released an update for EasyApache 4! Take a look at some highlights below, and then join us on the cPanel Community Forums, Discord, or Reddit to talk about this update and much more. If you have additional questions, feel free to reach out on one of our social channels.
-
ea-libxml2
-
EA-13548: Update ea-libxml2 from v2.15.3 to v2.15.4
-
(CVE-2026-86140) High: xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow
-
(CVE-2026-86138) Medium: xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow
-
(CVE-2026-86139) Medium: xmlURIEscapeStr in uri.c has an integer overflow
-
(CVE-2026-86142) Medium: heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation
-
(CVE-2026-86143) Medium: an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks
-
(CVE-2026-86144) Medium: xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags
-
(CVE-2026-86137) Low: xmlFAParsePosCharGroup has an out-of-bounds read in the NXT macro in xmlregexp
-
(CVE-2026-86141) Low: NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure
-
ea-nginx
-
EA-13546: Update ea-nginx from v1.31.4 to v1.31.5
-
ea-nginx-echo
-
EA-13546: Build against ea-nginx version v1.31.5
-
ea-nginx-headers-more
-
EA-13546: Build against ea-nginx version v1.31.5
-
ea-nginx-njs
-
EA-13545: Update ea-nginx-njs from v1.0.0 to v1.0.1
-
ea-nginx-passenger
-
EA-13546: Build against ea-nginx version v1.31.5
-
ea-modsec30-connector-nginx
-
EA-13546: Build against ea-nginx version v1.31.5
-
ea-podman
-
EA4-319: Add compatibility for cagefs 7.6.39. CageFS 7.6.39 and later mask user@.service
-
deliberately (CloudLinux CLOS-4517), which left lingering accounts with no per-user systemd
-
manager, so rootless container sessions could not be prepared and WebApp deploys failed.
-
EA4-319: Containers now come back after a reboot on such a host.
-
ea-ruby27 (CentOS 7 and CentOS 8 only)
-
EA-13547: Patch ea-ruby27 for multiple CVEs in resolv
-
(CVE-2026-80212) High: memory exhaustion through malicious DNS responses
-
(CVE-2026-80213) Medium: hostname validation bypass via oversized DNS names
Post is closed for comments.
Comments
0 comments