Does the Sept. 2 Apache Status article apply to CPANEL-54008 / CSF whm-server-status?
Hi,
I'm trying to understand how this newer cPanel article relates to the existing CSF bug, CPANEL-54008:
Apache Status displaying "Failed to receive status information from Apache." when using a custom Apache template
https://support.cpanel.net/hc/en-us/articles/41603699780375-Apache-Status-displaying-Failed-to-receive-status-information-from-Apache-when-using-a-custom-Apache-template
and this existing thread:
CSF bug with whm-server-status
https://support.cpanel.net/hc/en-us/community/posts/41451717897879-CSF-bug-with-whm-server-status
The September 2 article says that in cPanel v136 the whm-server-status endpoint was obfuscated for security, and specifically says that trying to access the old URL with a third-party tool will generate an error.
That sounds very much like what CSF/LFD is doing in CPANEL-54008.
In the original thread, cPanel confirmed CPANEL-54008 on June 24 and said on August 12 that a fix was in place and going through final testing. I posted there again on September 9 but have not received a response.
I am still seeing this on two cPanel servers. Both received cpanel-csf 16.31-1.2.1.cpanel automatically on September 3. Immediately after LFD restarted, both servers began logging this once every minute:
STATS: Unable to retrieve Apache Server Status [...] - Unable to download: Not Found
Both servers also use the cPanel NGINX reverse proxy. NGINX listens on 80/443 and Apache listens on 8080/8443. I don't know whether NGINX changes the recommended solution, which is one reason I don't want to start modifying Apache configuration without knowing what cPanel recommends.
I have confirmed that Apache status itself is working. For example:
curl http://127.0.0.1:8080/whm-server-status?auto
returns HTTP 200 and the normal Apache status information on both servers.
So I'm hoping someone from cPanel, perhaps cPRex can clarify:
- Is the September 2 article describing the same underlying change that caused CPANEL-54008?
- Is CSF/LFD supposed to be using the new obfuscated whm-server-status URL?
- Has the CPANEL-54008 fix mentioned on August 12 actually been released?
- If it has not, what is the supported workaround for a server using the cPanel NGINX reverse proxy?
There is a /server-status workaround in the original thread which cPanel confirmed works, but I would rather not guess how that workaround should be applied with NGINX and Apache on port 8080.
I also noticed this newer September 15 article:
WHM Apache Status page shows: "Failed to receive status information from Apache."
https://support.cpanel.net/hc/en-us/articles/41878700253591-WHM-Apache-Status-page-shows-Failed-to-receive-status-information-from-Apache
That article says an outdated ea-apache24-config-runtime package can cause an Apache Status failure. Is that related to CPANEL-54008, or is it a separate issue?
This isn't just an occasional warning. LFD is generating the failed Apache Status request every minute on every server, so every hourly Log Scanner Report is being filled with roughly 60 copies of the same error.
Many thanks for any clarification!
-
Hey there! I've reached out to the CSF team about this for some clarification and I'll let you know once I have more details.
1 -
Thank you. The issues seem very closely related.
0 -
Sorry about the delay on this - we had some (all good) personnel changes on the CSF team so my response was a bit delayed. I'll answer these in order, and end with some good news.
- Yes, the September 2 article is describing the same change behind CPANEL-54008: v136 obfuscated
whm-server-status, so any tool still requesting the old static URL (LFD included) gets a 404. - Not currently. CSF/LFD is still shipped pointing at the legacy
whm-server-statusURL by default. Updating that is the pending fix. - Looking into the 16.31-1 release, I can confirm that was a security-only patch (CVE-2026-67402, the MESSENGER issue) and did not include the CPANEL-54008 fix. So no, it hasn't shipped yet.
- The NGINX reverse proxy doesn't change the recommended workaround, since PT_APACHESTATUS talks to Apache directly rather than through the proxy. You'd apply the same
/server-statusLocation block to your port-8080 Apache template and set:PT_APACHESTATUS = "http://127.0.0.1:8080/server-status"
then restart both Apache and CSF/LFD.
Separately, the September 15 article about
ea-apache24-config-runtimeis an unrelated issue (an outdated package causing the WHM Apache Status page itself to fail) not the same bug, so no action needed there unless you're seeing that specific symptom too.THE GOOD NEWS - the fix should be shipping in tomorrow's cPanel build if everything goes well!
0 - Yes, the September 2 article is describing the same change behind CPANEL-54008: v136 obfuscated
-
Thank you so much for the update!
0 -
You're very welcome!!
0
Please sign in to leave a comment.
Comments
5 comments