-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 SUMMARY WebPros International, LLC has updated packages for EasyApache 4 with updated versions of ModSecurity 2, PHP 8.4, PHP 8.3, PHP 8.2, and PHP 8.1 . This release addresses vulnerabilities related to CVE-2025-52891, CVE-2025-1735, CVE-2025-6491, and CVE-2025-1220. We strongly encourage all ModSecurity 2 users to update to version 2.9.11, all PHP 8.4 users to update to version 8.4.10, all PHP 8.3 users to update to version 8.3.23, all PHP 8.2 users to update to version 8.2.29, and all PHP 8.1 users to update to version 8.1.33. AFFECTED VERSIONS All versions of ModSecurity 2 through 2.9.10. All versions of PHP 8.4 through 8.4.8. All versions of PHP 8.3 through 8.3.22. All versions of PHP 8.2 through 8.2.28. All versions of PHP 8.1 through 8.1.32. SECURITY RATING The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2025-52891 - MEDIUM ModSecurity 2.9.11 Fixed vulnerability related to CVE-2025-52891. CVE-2025-1735 - MEDIUM PHP 8.4.10 Fixed vulnerability related to CVE-2025-1735. PHP 8.3.23 Fixed vulnerability related to CVE-2025-1735. PHP 8.2.29 Fixed vulnerability related to CVE-2025-1735. PHP 8.1.33 Fixed vulnerability related to CVE-2025-1735. CVE-2025-6491 - MEDIUM PHP 8.4.10 Fixed vulnerability related to CVE-2025-6491. PHP 8.3.23 Fixed vulnerability related to CVE-2025-6491. PHP 8.2.29 Fixed vulnerability related to CVE-2025-6491. PHP 8.1.33 Fixed vulnerability related to CVE-2025-6491. CVE-2025-1220 - MEDIUM PHP 8.4.10 Fixed vulnerability related to CVE-2025-1220. PHP 8.3.23 Fixed vulnerability related to CVE-2025-1220. PHP 8.2.29 Fixed vulnerability related to CVE-2025-1220. PHP 8.1.33 Fixed vulnerability related to CVE-2025-1220. SOLUTION WebPros International, LLC has released updated packages for EasyApache 4 25.22 on 2025 July 9, with ModSecurity 2 version 2.9.11, PHP 8.4.10, PHP 8.3.23, PHP 8.2.29, and PHP 8.1.33. Unless you have enabled automatic package updates in your cron, update your system with either your package manager or WHM's Run System Update interface. REFERENCES https://www.cve.org/CVERecord?id=CVE-2025-52891 https://www.cve.org/CVERecord?id=CVE-2025-1735 https://www.cve.org/CVERecord?id=CVE-2025-6491 https://www.cve.org/CVERecord?id=CVE-2025-1220 https://github.com/owasp-modsecurity/ModSecurity/releases https://www.php.net/ChangeLog-8.php#8.4.10 https://www.php.net/ChangeLog-8.php#8.3.23 https://www.php.net/ChangeLog-8.php#8.2.29 https://www.php.net/ChangeLog-8.php#8.1.33 -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEtnCbTMb0IHf2mEGRlSG+3KvZTd8FAmhusn4ACgkQlSG+3KvZ Td/qSA//V+1iq3TIJhmfGN6EOCE3A+JDW+YGscE+LqouQyEsDMAd/mlQNyXs0I/z vcz2Ffvj8+xaHvbiB2eifokXXvwahoJzzPFzehSXCawnBNf6nU+o55006Yx+GyB6 IHnrWiKM/PnwDER4HOkFFXAMj99GqIrTAGSOi4UzWFrH6VnnW0JoVBNMbNajdtKu iwBPuvup74vv7exB4o/CbfWojTZnHnZJpfi5A+7xHink4d/OMmyd5QgLK0CeNXhx 6vDY15sKLnyLeFoHojkHTzS4pZkCenOsYQBl2peg4/vVCoXCMp9G6HkBzgB8o4c8 6ie8PvRUzo3UmoS0bANheMyGT4jB6REjCQzhDD6ma0qOAraMRzRqzPo9s2TLSSzu Cc+jR7wib4SMTLyjtiNFxb8hopCx63tgtxYQG77UeiPI+G2WUE2EvqG1+xbprtIX ATxaABYoQO4r2TamNKlPQAKyg0u/NVs9WiYWjkOpnzTAidkDtKdY1SFl9Ku5uxVZ 0LYFTiUwRlF1G6/seRno+S7NB+5Z+6yt5EacosCSqVjysYOspZc4vcstAJaI+gMm OF/mtEtjTolyA/so++BIaa7tfNb4KIc2Kc+Ztn9tI7vEJy1nIfnLw5BMcHpgdjdu KXUA09HS3GsrmGaNlIjeGgx2V7+VFv+NPb+D+YS/Rgsh7/5JHTg= =FCLP -----END PGP SIGNATURE-----