You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The published Black-HOST v15.03 HTTPS template contains the same system-binary CGI mapping as cPanel 16.30. cPanel 16.31 removes it.
Changes
Remove the unsafe alias from the shipped Apache HTTPS template.
Filter literal ScriptAlias mappings to /usr/bin when the shared Messenger generator reads Apache main/HTTP/HTTPS templates. This also fixes retained v15.03/customized templates used by all panel installers, without overwriting administrator files. Whitespace, directive case, quoted arguments, trailing directory slashes and continued directives are covered.
Document the required CSF/LFD restart, effective Apache configuration verification, and the stale-include caveat when Messenger has already been disabled.
Add unit regressions and an isolated Apache/PHP/TLS integration test to CI. The main tests.yml workflow now uses a security discovery job feeding a security-tests matrix, currently containing messenger, matching the existing unit → tests graph. Suites are auto-discovered from .github/tests/security/*/Dockerfile and run through their sibling run.sh.
This deliberately addresses the named CVE, not the full cPanel 16.31 hardening set. No cPanel-only Perl dependencies, version bump, release publication or deployment are included.
Validation
GitHub CI: all 30 checks passed for commit 86ce8c0958419e2386efe4b296e770b314085915 (run), including the new Messenger security integration, individual unit tests, install/upgrade/smoke/uninstall and the distro matrix.
Messenger module perl -c: PASS, using a test-only configuration stub because a bare compile loads installed /etc/csf/csf.conf on startup.
Perl syntax checks for the new unit test and integration driver: PASS.
bash -n and ShellCheck for the integration shell script: PASS.
Workflow YAML parse and git diff --check: PASS.
Debian 12 / Apache 2.4 / PHP 8.2 integration in a disposable --network none Docker container: PASS. A harmless CGI fixture is reachable with the old unfiltered reader, then inaccessible through that mapping after the fix. Tests cover two TLS virtual hosts, PHP block-page behavior, retained customized template bytes, repeatable regeneration and the fresh template.
The integration test does not exercise live firewall redirection, every control-panel/PHP-handler combination, or Google's reCAPTCHA service. No production hosts were touched.
Upgrade note
The shared generator is the upgrade boundary: changing only the distributed template would miss installed templates because all seven installers preserve them. The unsafe directive is omitted from generated configuration even if the original administrator-owned template retains it. Existing Apache workers must load regenerated configuration; manual installation by itself is not remediation. See SECURITY.md for the operational steps.
Review
codex review --uncommitted completed with exit 0 and no actionable findings. The reviewer independently checked the template call sites and focused regressions; the completed local unit suite and Docker integration provide the broader runtime proof.
Workflow organization follow-up (September 11)
The Actions graph uses security → Matrix: security-tests, currently containing messenger, matching unit → tests. The previous head (24096e8) completed all 31/31 CI checks successfully (run).
Commit 293b1c7d46d64fcf0500d4f791b8a4a9fcda0271 reorganizes the security suite without changing its assertions or product code:
Dockerfile provides Apache/PHP/Perl; run.sh owns fixtures, scenarios, and assertions; driver.pl calls the real Messenger generator with controlled test settings. Only legacy-control substitutes the old template reader.
Fixed the deeper relative paths for the checkout and TestBootstrap, and resolved the driver relative to run.sh.
CI auto-discovers security/*/Dockerfile and executes the sibling run.sh; the manual .github/security.json manifest is no longer needed. The discovery/matrix graph, job names, fail-fast: false, read-only checkout, and container network isolation are preserved.
Updated the test README with the layout, local commands, and the driver's role.
Local validation: PASS for workflow actionlint, Bash syntax, ShellCheck, Perl syntax, actual suite discovery, path checks, and git diff --check. The real Docker/Apache/PHP integration passed from the renamed paths: legacy positive control, patched TLS routing, PHP pages, retained custom-template bytes, repeated regeneration, and fresh templates. No new test cases or production-code changes were needed.
Current CI run: security, messenger, and all 16 unit-test matrix jobs passed on 293b1c7. The remaining install/lifecycle and distro checks are still running.
The published v15.03 release and current main contain the affected Messenger v3 HTTPS configuration described in the cPanel advisory. This PR fixes both the shipped template and configuration generation from retained/customized templates, covering the upgrade path without overwriting administrator files.
The follow-up cleanup is complete: security/messenger/{Dockerfile,run.sh,driver.pl}, with folder-discovered CI. On the latest commit (293b1c7), local Apache/PHP integration, GitHub security, messenger, and all 16 unit jobs passed. The remaining CI checks are running; the preceding head passed all 31 checks.
Please consider this for a security release after review. Messenger is disabled by default, but affected enabled installations need the fix and configuration regeneration/reload described in SECURITY.md.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix the Messenger v3 Apache CGI mapping described by CVE-2026-67402 and the September 3 cPanel advisory.
The published Black-HOST v15.03 HTTPS template contains the same system-binary CGI mapping as cPanel 16.30. cPanel 16.31 removes it.
Changes
ScriptAliasmappings to/usr/binwhen the shared Messenger generator reads Apache main/HTTP/HTTPS templates. This also fixes retained v15.03/customized templates used by all panel installers, without overwriting administrator files. Whitespace, directive case, quoted arguments, trailing directory slashes and continued directives are covered.tests.ymlworkflow now uses a security discovery job feeding a security-tests matrix, currently containing messenger, matching the existingunit → testsgraph. Suites are auto-discovered from.github/tests/security/*/Dockerfileand run through their siblingrun.sh.This deliberately addresses the named CVE, not the full cPanel 16.31 hardening set. No cPanel-only Perl dependencies, version bump, release publication or deployment are included.
Validation
GitHub CI: all 30 checks passed for commit
86ce8c0958419e2386efe4b296e770b314085915(run), including the new Messenger security integration, individual unit tests, install/upgrade/smoke/uninstall and the distro matrix.prove -r .github/tests/unit/: 16 files, 86 top-level tests, PASS.Messenger module
perl -c: PASS, using a test-only configuration stub because a bare compile loads installed/etc/csf/csf.confon startup.Perl syntax checks for the new unit test and integration driver: PASS.
bash -nand ShellCheck for the integration shell script: PASS.Workflow YAML parse and
git diff --check: PASS.Debian 12 / Apache 2.4 / PHP 8.2 integration in a disposable
--network noneDocker container: PASS. A harmless CGI fixture is reachable with the old unfiltered reader, then inaccessible through that mapping after the fix. Tests cover two TLS virtual hosts, PHP block-page behavior, retained customized template bytes, repeatable regeneration and the fresh template.The integration test does not exercise live firewall redirection, every control-panel/PHP-handler combination, or Google's reCAPTCHA service. No production hosts were touched.
Upgrade note
The shared generator is the upgrade boundary: changing only the distributed template would miss installed templates because all seven installers preserve them. The unsafe directive is omitted from generated configuration even if the original administrator-owned template retains it. Existing Apache workers must load regenerated configuration; manual installation by itself is not remediation. See
SECURITY.mdfor the operational steps.Review
codex review --uncommittedcompleted with exit 0 and no actionable findings. The reviewer independently checked the template call sites and focused regressions; the completed local unit suite and Docker integration provide the broader runtime proof.Workflow organization follow-up (September 11)
The Actions graph uses security → Matrix: security-tests, currently containing messenger, matching
unit → tests. The previous head (24096e8) completed all 31/31 CI checks successfully (run).Commit
293b1c7d46d64fcf0500d4f791b8a4a9fcda0271reorganizes the security suite without changing its assertions or product code:Dockerfileprovides Apache/PHP/Perl;run.showns fixtures, scenarios, and assertions;driver.plcalls the real Messenger generator with controlled test settings. Onlylegacy-controlsubstitutes the old template reader.TestBootstrap, and resolved the driver relative torun.sh.security/*/Dockerfileand executes the siblingrun.sh; the manual.github/security.jsonmanifest is no longer needed. The discovery/matrix graph, job names,fail-fast: false, read-only checkout, and container network isolation are preserved.Local validation: PASS for workflow
actionlint, Bash syntax, ShellCheck, Perl syntax, actual suite discovery, path checks, andgit diff --check. The real Docker/Apache/PHP integration passed from the renamed paths: legacy positive control, patched TLS routing, PHP pages, retained custom-template bytes, repeated regeneration, and fresh templates. No new test cases or production-code changes were needed.Current CI run: security, messenger, and all 16 unit-test matrix jobs passed on
293b1c7. The remaining install/lifecycle and distro checks are still running.