CVE-2026-48834

CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing

Vendor Apache Software Foundation
Product Apache Answer
Weakness CWE-400
Published August 5, 2026
Last update August 5, 2026

CVSS base score

What the vulnerability does

01Description

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Key dates

02Disclosure timeline

August 5, 2026 CVE published