The cPanel team has released EasyApache 3.36.11 with PHP version 5.6.39. This security update addresses vulnerabilities related to CVE-2018-19518 and CVE-2018-19935. It is highly recommended for all PHP 5.6 users to upgrade to version 5.6.39. Unless you have disabled EasyApache updates, the EasyApache application updates to the latest version when launched. Run EasyApache to rebuild your profile with the latest version of PHP.
All versions of PHP 5.6 through 5.6.38
The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs:
For more information, please make sure to visit the release notes and the official EasyApache 3 changelog.