AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-48834

HIGH · CVSS 7.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Apache Answer versions up to 2.0.1 are vulnerable to a denial of service attack due to improper handling of the Accept-Language header, allowing unauthenticated attackers to induce excessive CPU consumption. Organizations using this software should prioritize upgrading to version 2.0.2 to mitigate the risk of service disruption.

CVE
CVE-2026-48834
Severity
HIGH
CVSS
7.5
EPSS
0.49%
Apache

Original NVD Description

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)