Web hosting software cPanel: updates close security hole
Summary
In August 2025 the hosting control panel cPanel/WHM received updates for holes in bundled third-party software. Named were a prototype pollution hole in requirejs 2.3.6 (CVE-2024-38999) and a memory bug in SQLite before version 3.50.2 (CVE-2025-6965, CVSS 7.2). Branches 130, 128, 126, 118 and 110 were fixed.
Ideas
- Bundled libraries pass their holes on to the main product.
- Prototype pollution manipulates JavaScript objects, up to code execution.
- Several version branches maintained in parallel each need their own updates.
Insights
- A product’s supply chain includes every bundled library.
- Hosting platforms are a rewarding target because of their many customer accounts.
Facts
- The fixed versions were 130.0.5/6, 128.0.18, 126.0.28, 118.0.53 and 110.0.71.
- The SQLite hole affected versions before 3.50.2.
References
Critique
- The report does not say whether the holes were actually reachable in cPanel or only formally included.
Recommendations
- Keep a bill of materials of bundled libraries (SBOM) for the products you use.
- Enable automatic updates for hosting control panels or schedule fixed maintenance windows.
Links to the original source and the Web Archive open in a new tab.