bk99.de entertain the web since 1997

Web hosting software cPanel: updates close security hole

Summary

In August 2025 the hosting control panel cPanel/WHM received updates for holes in bundled third-party software. Named were a prototype pollution hole in requirejs 2.3.6 (CVE-2024-38999) and a memory bug in SQLite before version 3.50.2 (CVE-2025-6965, CVSS 7.2). Branches 130, 128, 126, 118 and 110 were fixed.

Ideas

  • Bundled libraries pass their holes on to the main product.
  • Prototype pollution manipulates JavaScript objects, up to code execution.
  • Several version branches maintained in parallel each need their own updates.

Insights

  • A product’s supply chain includes every bundled library.
  • Hosting platforms are a rewarding target because of their many customer accounts.

Facts

  • The fixed versions were 130.0.5/6, 128.0.18, 126.0.28, 118.0.53 and 110.0.71.
  • The SQLite hole affected versions before 3.50.2.

References

Critique

  • The report does not say whether the holes were actually reachable in cPanel or only formally included.

Recommendations

  • Keep a bill of materials of bundled libraries (SBOM) for the products you use.
  • Enable automatic updates for hosting control panels or schedule fixed maintenance windows.

Read the original article

Search the Web Archive