Skip to content

Fix CVE-2026-67402 in Messenger v3 Apache templates - #15

Merged
UptimeEnforcer merged 4 commits into
Black-HOST:mainfrom
zeroth-blip:fix/cve-2026-67402-messenger
Sep 11, 2026
Merged

UptimeEnforcer merged 4 commits into
Black-HOST:mainfrom
zeroth-blip:fix/cve-2026-67402-messenger

Conversation

@zeroth-blip

@zeroth-blip zeroth-blip commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fix the Messenger v3 Apache CGI mapping described by CVE-2026-67402 and the September 3 cPanel advisory.

The published Black-HOST v15.03 HTTPS template contains the same system-binary CGI mapping as cPanel 16.30. cPanel 16.31 removes it.

Changes

  • Remove the unsafe alias from the shipped Apache HTTPS template.
  • Filter literal ScriptAlias mappings to /usr/bin when the shared Messenger generator reads Apache main/HTTP/HTTPS templates. This also fixes retained v15.03/customized templates used by all panel installers, without overwriting administrator files. Whitespace, directive case, quoted arguments, trailing directory slashes and continued directives are covered.
  • Preserve unrelated directives, individual PHP CGI handlers, PHP block pages and native LiteSpeed templates.
  • Document the required CSF/LFD restart, effective Apache configuration verification, and the stale-include caveat when Messenger has already been disabled.
  • Add unit regressions and an isolated Apache/PHP/TLS integration test to CI. The main tests.yml workflow now uses a security discovery job feeding a security-tests matrix, currently containing messenger, matching the existing unit → tests graph. Suites are auto-discovered from .github/tests/security/*/Dockerfile and run through their sibling run.sh.

This deliberately addresses the named CVE, not the full cPanel 16.31 hardening set. No cPanel-only Perl dependencies, version bump, release publication or deployment are included.

Validation

  • GitHub CI: all 30 checks passed for commit 86ce8c0958419e2386efe4b296e770b314085915 (run), including the new Messenger security integration, individual unit tests, install/upgrade/smoke/uninstall and the distro matrix.

  • prove -r .github/tests/unit/: 16 files, 86 top-level tests, PASS.

  • Messenger module perl -c: PASS, using a test-only configuration stub because a bare compile loads installed /etc/csf/csf.conf on startup.

  • Perl syntax checks for the new unit test and integration driver: PASS.

  • bash -n and ShellCheck for the integration shell script: PASS.

  • Workflow YAML parse and git diff --check: PASS.

  • Debian 12 / Apache 2.4 / PHP 8.2 integration in a disposable --network none Docker container: PASS. A harmless CGI fixture is reachable with the old unfiltered reader, then inaccessible through that mapping after the fix. Tests cover two TLS virtual hosts, PHP block-page behavior, retained customized template bytes, repeatable regeneration and the fresh template.

The integration test does not exercise live firewall redirection, every control-panel/PHP-handler combination, or Google's reCAPTCHA service. No production hosts were touched.

Upgrade note

The shared generator is the upgrade boundary: changing only the distributed template would miss installed templates because all seven installers preserve them. The unsafe directive is omitted from generated configuration even if the original administrator-owned template retains it. Existing Apache workers must load regenerated configuration; manual installation by itself is not remediation. See SECURITY.md for the operational steps.

Review

codex review --uncommitted completed with exit 0 and no actionable findings. The reviewer independently checked the template call sites and focused regressions; the completed local unit suite and Docker integration provide the broader runtime proof.

Workflow organization follow-up (September 11)

The Actions graph uses security → Matrix: security-tests, currently containing messenger, matching unit → tests. The previous head (24096e8) completed all 31/31 CI checks successfully (run).

Commit 293b1c7d46d64fcf0500d4f791b8a4a9fcda0271 reorganizes the security suite without changing its assertions or product code:

.github/tests/security/messenger/
├── Dockerfile
├── run.sh
└── driver.pl
  • Dockerfile provides Apache/PHP/Perl; run.sh owns fixtures, scenarios, and assertions; driver.pl calls the real Messenger generator with controlled test settings. Only legacy-control substitutes the old template reader.
  • Fixed the deeper relative paths for the checkout and TestBootstrap, and resolved the driver relative to run.sh.
  • CI auto-discovers security/*/Dockerfile and executes the sibling run.sh; the manual .github/security.json manifest is no longer needed. The discovery/matrix graph, job names, fail-fast: false, read-only checkout, and container network isolation are preserved.
  • Updated the test README with the layout, local commands, and the driver's role.

Local validation: PASS for workflow actionlint, Bash syntax, ShellCheck, Perl syntax, actual suite discovery, path checks, and git diff --check. The real Docker/Apache/PHP integration passed from the renamed paths: legacy positive control, patched TLS routing, PHP pages, retained custom-template bytes, repeated regeneration, and fresh templates. No new test cases or production-code changes were needed.

Current CI run: security, messenger, and all 16 unit-test matrix jobs passed on 293b1c7. The remaining install/lifecycle and distro checks are still running.

@zeroth-blip

Copy link
Copy Markdown
Contributor Author

@UptimeEnforcer could you prioritize reviewing this PR for CVE-2026-67402?

The published v15.03 release and current main contain the affected Messenger v3 HTTPS configuration described in the cPanel advisory. This PR fixes both the shipped template and configuration generation from retained/customized templates, covering the upgrade path without overwriting administrator files.

The follow-up cleanup is complete: security/messenger/{Dockerfile,run.sh,driver.pl}, with folder-discovered CI. On the latest commit (293b1c7), local Apache/PHP integration, GitHub security, messenger, and all 16 unit jobs passed. The remaining CI checks are running; the preceding head passed all 31 checks.

Please consider this for a security release after review. Messenger is disabled by default, but affected enabled installations need the fix and configuration regeneration/reload described in SECURITY.md.

@UptimeEnforcer

Copy link
Copy Markdown
Member

@zeroth-blip thanks for the PR reviewing it now.

@UptimeEnforcer

Copy link
Copy Markdown
Member

@zeroth-blip looks good, nice job on the security tests.

@UptimeEnforcer
UptimeEnforcer merged commit 13ce216 into Black-HOST:main Sep 11, 2026
31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants