CVE-2026-48834 PUBLISHED

Apache Answer: Denial of service via crafted Accept-Language header parsing

Assigner: apache
Reserved: 25.05.2026 Published: 05.08.2026 Updated: 05.08.2026

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.1.

Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Answer
Versions Default: unaffected
  • affected from 0 to 2.0.1 (incl.)

Credits

  • tonghuaroot reporter

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE