☀️ Summer New Offers are LIVE! → 🎁 Open our Offers Page & get exciting deals with flat upto 20-30% OFF on all products → 🚀 Boost your hosting with faster, secure & reliable services at DotShift → 🔥 Don’t miss limited-time summer discounts across hosting, VPS, reseller & more → 👉 Visit Now: https://dotshift.net/offers 🎉     
Login
Offers

Security Update, Affected Versions & Immediate Fix Instructions

⚠️ Critical cPanel Security Update

A vulnerability was discovered in cpsrvd that could allow insertion of arbitrary HTTP headers through an unauthenticated endpoint.

🔍 Vulnerability Overview

The issue affects cPanel & WHM version 132 and later.

Due to insufficient validation inside the cpsrvd service, attackers may inject arbitrary HTTP headers through unauthenticated requests.

While limited technical details are currently public, arbitrary header injection vulnerabilities can potentially lead to cache poisoning, security bypasses, request manipulation, and other web security risks.

🚨 Potential Impact

  • Arbitrary HTTP header injection
  • Unauthenticated request manipulation
  • Potential cache poisoning
  • Security policy bypass possibilities
  • Unexpected proxy or redirect behavior

✅ Patched cPanel Versions

11.132.0.32+
11.134.0.26+
11.136.0.10+
WP Squared patched version:
11.136.1.12 and higher

🛠️ How to Update cPanel

Run the following command as root to install the latest patched version:

/scripts/upcp --force

After the update completes, verify the installed cPanel version:

/usr/local/cpanel/cpanel -V

🔒 Additional Security Fixes Included

This latest cPanel release also resolves additional security vulnerabilities:

CVE-2026-29205
CVE-2026-29206
CVE-2026-32991
CVE-2026-32992
🔒 Security Recommendation

Update all production cPanel servers immediately and ensure automatic updates are enabled for security releases.

📄 Official References
cPanel Changelogs
⚠️ Final Security Warning:
Servers running outdated cPanel versions may remain vulnerable to HTTP header injection and additional undisclosed security issues fixed in the latest release.