EasyApache4 v25.86 Maintenance and Security Release
PinnedWebPros has released an update for EasyApache 4! Take a look at some highlights below, and then join us on the cPanel Community Forums, Discord, or Reddit to talk about this update and much more. If you have additional questions, feel free to reach out on one of our social channels.
-
ea-php82
-
EA-13567: Update ea-php82 from v8.2.33 to v8.2.34
-
(CVE-2025-1218) Low: Various packet overreads in mysqlnd wire protocol
-
(CVE-2025-14181) Medium: Integer overflow to buffer overflow in SOAP HTTP parsing
-
(CVE-2026-6103) Medium: Integer overflow in phar_tar_number() allowing TAR archive entry injection
-
(CVE-2026-17545) Medium: Reserved device names are not rejected before file and stream I/O on Windows
-
(CVE-2026-91765) High: Unbounded recursion in server-side cleanup_xml_node()
-
(CVE-2026-91766) Medium: Cross-origin credential leak in HTTP stream wrapper redirects
-
(CVE-2026-91767) Medium: Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN
-
(CVE-2026-91768) Medium: IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison
-
(CVE-2026-91769) Medium: TLS hostname verification falls back to CN after SAN mismatch
-
(CVE-2026-92842) Medium: Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL
-
(CVE-2026-93682) Medium: Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header
-
Low: FILTER_SANITIZE_ENCODED does not encode 0xFF (backported fix, GHSA-ch8v-r6jh-4vvr, no CVE assigned)
-
ea-php82-meta
-
EA-13567: Update ea-php82 from v8.2.33 to v8.2.34
-
ea-php83
-
EA-13568: Update ea-php83 from v8.3.33 to v8.3.35
-
(CVE-2025-1218) Low: Various packet overreads in mysqlnd wire protocol
-
(CVE-2025-14181) Medium: Integer overflow to buffer overflow in SOAP HTTP parsing
-
(CVE-2026-6103) Medium: Integer overflow in phar_tar_number() allowing TAR archive entry injection
-
(CVE-2026-17545) Medium: Reserved device names are not rejected before file and stream I/O on Windows
-
(CVE-2026-91765) High: Unbounded recursion in server-side cleanup_xml_node()
-
(CVE-2026-91766) Medium: Cross-origin credential leak in HTTP stream wrapper redirects
-
(CVE-2026-91767) Medium: Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN
-
(CVE-2026-91768) Medium: IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison
-
(CVE-2026-91769) Medium: TLS hostname verification falls back to CN after SAN mismatch
-
(CVE-2026-92842) Medium: Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL
-
(CVE-2026-93682) Medium: Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header
-
Low: FILTER_SANITIZE_ENCODED does not encode 0xFF (backported fix, GHSA-ch8v-r6jh-4vvr, no CVE assigned)
-
ea-php83-meta
-
EA-13568: Update ea-php83 from v8.3.33 to v8.3.35
-
ea-php84
-
EA-13569: Update ea-php84 from v8.4.25 to v8.4.26
-
(CVE-2025-1218) Low: Various packet overreads in mysqlnd wire protocol
-
(CVE-2025-14181) Medium: Integer overflow to buffer overflow in SOAP HTTP parsing
-
(CVE-2026-6103) Medium: Integer overflow in phar_tar_number() allowing TAR archive entry injection
-
(CVE-2026-17545) Medium: Reserved device names are not rejected before file and stream I/O on Windows
-
(CVE-2026-91765) High: Unbounded recursion in server-side cleanup_xml_node()
-
(CVE-2026-91766) Medium: Cross-origin credential leak in HTTP stream wrapper redirects
-
(CVE-2026-91767) Medium: Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN
-
(CVE-2026-91768) Medium: IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison
-
(CVE-2026-91769) Medium: TLS hostname verification falls back to CN after SAN mismatch
-
(CVE-2026-92842) Medium: Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL
-
(CVE-2026-93682) Medium: Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header
-
ea-php84-meta
-
EA-13569: Update ea-php84 from v8.4.25 to v8.4.26
-
ea-php85
-
EA-13565: Update ea-php85 from v8.5.10 to v8.5.11
-
(CVE-2025-1218) Low: Various packet overreads in mysqlnd wire protocol
-
(CVE-2025-14181) Medium: Integer overflow to buffer overflow in SOAP HTTP parsing
-
(CVE-2026-6103) Medium: Integer overflow in phar_tar_number() allowing TAR archive entry injection
-
(CVE-2026-17545) Medium: Reserved device names are not rejected before file and stream I/O on Windows
-
(CVE-2026-91765) High: Unbounded recursion in server-side cleanup_xml_node()
-
(CVE-2026-91766) Medium: Cross-origin credential leak in HTTP stream wrapper redirects
-
(CVE-2026-91767) Medium: Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN
-
(CVE-2026-91768) Medium: IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison
-
(CVE-2026-91769) Medium: TLS hostname verification falls back to CN after SAN mismatch
-
(CVE-2026-92842) Medium: Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL
-
(CVE-2026-93682) Medium: Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header
-
ea-php85-meta
-
EA-13565: Update ea-php85 from v8.5.10 to v8.5.11
-
ea-nodejs22
-
EA-13564: Update ea-nodejs22 from v22.23.2 to v22.23.3
-
ea-ruby27-libuv
-
EA-13570: Update ea-ruby27-libuv from v1.52.1 to v1.53.0
-
ea-podman
-
EA4-325: Make `ea-podman upgrade` skip a recreate when nothing has moved, recreate a container whose backup failed to come back up or whose create failed without deregistering it or releasing its ports, and still recreate a web app published on every interface
Post is closed for comments.
Comments
0 comments