Back to Security Advisories
Medium 2026-08-07

EasyApache 4 25.64 — cPanel & WHM Update

cPanel

Security and maintenance updates We released updated packages for EasyApache 4. This security release patches CVE-2026-49975 in ea-apache24. Attackers can craft malicious HTTP/2 cookie headers that multiply across streams, consuming excessive memory. The fix makes cookie headers count against LimitRequestFields. Not…

Affected Versions

25.64

Security and maintenance updates We released updated packages for EasyApache 4. This security release patches CVE-2026-49975 in ea-apache24. Attackers can craft malicious HTTP/2 cookie headers that multiply across streams, consuming excessive memory. The fix makes cookie headers count against LimitRequestFields. Not…

EasyApache 4 25.64

2026 June 3

Security and maintenance updates

We released updated packages for EasyApache 4.

This security release patches CVE-2026-49975 in ea-apache24. Attackers can craft malicious HTTP/2 cookie headers that multiply across streams, consuming excessive memory. The fix makes cookie headers count against LimitRequestFields. Note: HTTP/2 is not enabled by default in cPanel configurations.

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force
More Information

Check your system for vulnerabilities

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

Check Your System