ConfigServer Security & Firewall (CSF) 16.31-1
Targeted Security Release For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Targeted Security Release For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Maintenance and security updates We released updated packages for EasyApache 4. This release patches ea-openssl11 on CentOS 7 for a heap buffer overflow in CMS key unwrapping (CVE-2026-63072) and excessive memory use when buffering DTLS re…
Maintenance and security updates We released updated packages for EasyApache 4. This release updates ea-nginx to v1.31.4, which adds PROXY protocol version 2 support to the stream and mail modules, sends the ":authority" pseudo-h…
Security and maintenance updates We released updated packages for EasyApache 4. This security release hardens the Phusion Passenger agent API authorization boundary so an empty API account database confers no privileges, resolving a local …
Security fix This release validates that Sitejet single sign-on links point to the expected Sitejet host before use (DUCKS-6701). For a full list of changes, read the Sitejet Builder change log.
Maintenance and Security Release We released updated packages for EasyApache 4. This release hardens container isolation, authorization, and registry integrity in ea-podman (CPANEL-55335, CPANEL-55336, CPANEL-55337, CPANEL-55342, CPANEL-55…
Maintenance and Security Release We released updated packages for EasyApache 4. This release resolves three PHP vulnerabilities across ea-php82, ea-php83, ea-php84, and ea-php85: a libgd vulnerability (CVE-2026-9672), a SQL injection via b…
Security fixes This security release resolves several vulnerabilities in CSF (CPANEL-54191, CPANEL-55183, CPANEL-54192, CPANEL-55265). It also includes several firewall reliability fixes for AlmaLinux 10, Debian, and Ubuntu. For a full lis…
Faster site publishing Sitejet Builder now downloads website files in parallel when you publish a site. This reduces publish time for large sites. For a full list of changes, read the Sitejet Builder change log.
Maintenance updates We released updated packages for EasyApache 4. This maintenance release includes updates to ea-passenger-src (v6.1.8), ea-ruby27-passenger (v6.1.8), ea-redis62 (v6.2.23), ea-valkey72 (v7.2.14), ea-memcached16 (v1.6.45),…
Introduced the Meridian interface We introduced Meridian, a new goal-based cPanel interface. Meridian organizes common hosting tasks into six purpose-built hubs for Websites, Email, Files, Databases, Security, and Performance. Its Dashboar…
Security Hotfix We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4. This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular express…
Maintenance updates We released updated ea-tomcat101, ea-memcached16, ea-apache24-mod_security2, ea-modsec2-rules-owasp-crs, ea-ioncube15, ea-nodejs22, and Phusion Passenger 6.1.7 (ea-passenger-src, ea-ruby27-passenger, ea-apache24-mod-pas…
Maintenance updates We released updated ea-modsec30, ea-modsec30-connector-apache24, and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This maintenance release fixes ModSecurity audit logs silently failing to write across mod_ruid…
Bug fixes This release fixes Comet Backup jobs failing en masse with locked-by-device retention errors on busy servers. The plugin now requests the less-often automatic-retention ruleset for dispatched backups and no longer cancels orphan…
Security hotfix We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body pars…
Improved read-only API token enforcement Sitejet Builder UAPI methods are now classified as read-only for cPanel & WHM API token enforcement. For a full list of changes, read the Sitejet Builder change log.
Security and maintenance updates We released updated packages for EasyApache 4. This security release updates PHP 8.2, 8.3, 8.4, and 8.5 to address CVE-2026-14355 (a memory corruption issue in openssl_encrypt with AES-WRAP-PAD) and, for PH…
Security and maintenance updates We released an updated ea-tomcat101 package for EasyApache 4. This security release updates Apache Tomcat to 10.1.56, addressing six CVEs (CVE-2026-55956, CVE-2026-55955, CVE-2026-55276, CVE-2026-53434, CVE…
AWS partner rollout Server Monitoring rollout for the AWS partner. For a full list of changes, read the Server Monitoring change log.