Impact
Apache Answer versions up to 2.0.1 exhibit an improper handling of a length parameter inconsistency in the parsing of the Accept-Language header. An attacker who can send a crafted header can cause the server to consume excessive CPU resources while parsing, degrading service availability.
Affected Systems
The vulnerability affects Apache Answer through version 2.0.1. The affected vendor is Apache Software Foundation and the product is Apache Answer. Version 2.0.2 and later contain a fix.
Risk and Exploitability
The vulnerability can be triggered by unauthenticated attackers. While no EPSS score is available and the issue is not listed in the CISA KEV catalog, the potential for high CPU consumption indicates a real risk of resource exhaustion. The lack of a published CVSS score makes precise severity grading difficult, but the denial‑of‑service impact coupled with easy remote trigger suggests an urgent remedial action.
OpenCVE Enrichment