CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing
Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Answerto a version that resolves this vulnerability.Fixed in 2.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48834?
The severity of CVE-2026-48834 is rated as 30, indicating a significant risk of denial of service.
How do I fix CVE-2026-48834?
To fix CVE-2026-48834, update to a patched version of Apache Answer beyond 2.0.1 that addresses the vulnerability.
What impact does CVE-2026-48834 have on my Apache Answer installation?
CVE-2026-48834 can lead to excessive CPU consumption by your Apache Answer installation, resulting in a denial of service.
Who can exploit CVE-2026-48834?
CVE-2026-48834 can be exploited by unauthenticated attackers sending crafted Accept-Language headers.
When was CVE-2026-48834 published?
CVE-2026-48834 was published on August 5, 2026.