EasyApache 4 25.64 — cPanel & WHM Update
Affected Versions
25.64
What this means under a SharedLicense license
Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Apply it on every affected server: sudo /scripts/upcp --force. Licenses keep working through updates; nothing needs re-issuing or re-activating.
Security and maintenance updates We released updated packages for EasyApache 4. This security release patches CVE-2026-49975 in ea-apache24. Attackers can craft malicious HTTP/2 cookie headers that multiply across streams, consuming excessive memory. The fix makes cookie headers count against LimitRequestFields. Not…
EasyApache 4 25.64
2026 June 3
Security and maintenance updates
We released updated packages for EasyApache 4.
This security release patches CVE-2026-49975 in ea-apache24. Attackers can craft malicious HTTP/2 cookie headers that multiply across streams, consuming excessive memory. The fix makes cookie headers count against LimitRequestFields. Note: HTTP/2 is not enabled by default in cPanel configurations.
For a full list of changes, read the EasyApache 4 change log.
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System