CVE-2026-48834
Received Received - Intake

Denial of Service in Apache Answer Due to Length Parameter Handling

Vulnerability report for CVE-2026-48834, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Apache Software Foundation

Description

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache answer to 2.0.2 (exc)
apache answer 2.0.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service vulnerability in Apache Answer versions up to 2.0.1. It occurs when an unauthenticated attacker sends a specially crafted Accept-Language header that causes excessive CPU consumption during parsing, leading to system slowdown or crash.

Detection Guidance

Detect this vulnerability by monitoring CPU usage spikes when Apache Answer processes Accept-Language headers. Check for excessive parsing activity in logs or system monitoring tools.

Impact Analysis

Unauthenticated attackers could exploit this to disrupt Apache Answer services by consuming excessive server resources, causing downtime or degraded performance for legitimate users.

Mitigation Strategies

Upgrade Apache Answer to version 2.0.2 or later immediately to fix the vulnerability. If upgrading is not possible, restrict access to the server or implement rate limiting on header processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48834. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart