Description
Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.1.

Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing.
Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apache Answer versions up to 2.0.1 exhibit an improper handling of a length parameter inconsistency in the parsing of the Accept-Language header. An attacker who can send a crafted header can cause the server to consume excessive CPU resources while parsing, degrading service availability.

Affected Systems

The vulnerability affects Apache Answer through version 2.0.1. The affected vendor is Apache Software Foundation and the product is Apache Answer. Version 2.0.2 and later contain a fix.

Risk and Exploitability

The vulnerability can be triggered by unauthenticated attackers. While no EPSS score is available and the issue is not listed in the CISA KEV catalog, the potential for high CPU consumption indicates a real risk of resource exhaustion. The lack of a published CVSS score makes precise severity grading difficult, but the denial‑of‑service impact coupled with easy remote trigger suggests an urgent remedial action.

Generated by OpenCVE AI on August 5, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch by upgrading to Apache Answer 2.0.2 or later.
  • Reduce the maximum Accept‑Language header length or strip the header before parsing to limit resource use.
  • Monitor server CPU utilization for spikes and investigate any unexpected high usage to detect potential exploitation attempts.

Generated by OpenCVE AI on August 5, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache answer
Vendors & Products Apache
Apache answer

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Title Apache Answer: Denial of service via crafted Accept-Language header parsing
Weaknesses CWE-400
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T16:32:54.160Z

Reserved: 2026-05-25T11:13:04.242Z

Link: CVE-2026-48834

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T16:30:13Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption