Skip to main content

Does the Sept. 2 Apache Status article apply to CPANEL-54008 / CSF whm-server-status?

Comments

5 comments

  • cPRex Jurassic Moderator

    Hey there!  I've reached out to the CSF team about this for some clarification and I'll let you know once I have more details.

    1
  • Metro2

    Thank you. The issues seem very closely related.

    0
  • cPRex Jurassic Moderator

    Sorry about the delay on this - we had some (all good) personnel changes on the CSF team so my response was a bit delayed.  I'll answer these in order, and end with some good news.

    1. Yes, the September 2 article is describing the same change behind CPANEL-54008: v136 obfuscated whm-server-status, so any tool still requesting the old static URL (LFD included) gets a 404.
    2. Not currently.  CSF/LFD is still shipped pointing at the legacy whm-server-status URL by default. Updating that is the pending fix.
    3. Looking into the 16.31-1 release, I can confirm that was a security-only patch (CVE-2026-67402, the MESSENGER issue) and did not include the CPANEL-54008 fix. So no, it hasn't shipped yet.
    4. The NGINX reverse proxy doesn't change the recommended workaround, since PT_APACHESTATUS talks to Apache directly rather than through the proxy. You'd apply the same /server-status Location block to your port-8080 Apache template and set:
      PT_APACHESTATUS = "http://127.0.0.1:8080/server-status"
      then restart both Apache and CSF/LFD.

    Separately, the September 15 article about ea-apache24-config-runtime is an unrelated issue (an outdated package causing the WHM Apache Status page itself to fail) not the same bug, so no action needed there unless you're seeing that specific symptom too.

    THE GOOD NEWS - the fix should be shipping in tomorrow's cPanel build if everything goes well!

    0
  • Metro2

    Thank you so much for the update!

    0
  • cPRex Jurassic Moderator

    You're very welcome!!

    0

Please sign in to leave a comment.