Description
Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.1.

Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing.
Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apache Answer versions up to 2.0.1 exhibit an improper handling of a length parameter inconsistency in the parsing of the Accept‑Language header. An attacker who can send a crafted header can cause the server to consume excessive CPU resources while parsing, degrading service availability.

Affected Systems

The vulnerability affects Apache Answer through version 2.0.1. The affected vendor is Apache Software Foundation and the product is Apache Answer. Version 2.0.2 and later contain a fix.

Risk and Exploitability

The vulnerability can be triggered by unauthenticated attackers. The CVSS score is 7.5, classifying it as high severity. The EPSS score is 0.00181, indicating a very low but non‑zero probability of exploitation. The denial‑of‑service impact coupled with the easy remote trigger suggests an urgent remedial action.

Generated by OpenCVE AI on August 6, 2026 at 17:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch by upgrading to Apache Answer 2.0.2 or later.
  • Configure the web server or an upstream reverse proxy to reject Accept‑Language headers that exceed a safe length threshold.
  • Monitor incoming requests and CPU usage for sudden spikes, blocking or rate‑limiting connections that send oversized or malformed Accept‑Language headers.

Generated by OpenCVE AI on August 6, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache answer
Vendors & Products Apache
Apache answer

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Title Apache Answer: Denial of service via crafted Accept-Language header parsing
Weaknesses CWE-400
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-06T14:35:47.589Z

Reserved: 2026-05-25T11:13:04.242Z

Link: CVE-2026-48834

cve-icon Vulnrichment

Updated: 2026-08-05T16:32:54.160Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T16:16:56.980

Modified: 2026-08-06T18:38:23.447

Link: CVE-2026-48834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T18:00:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption