Security Advisory

CVE-2026-48834

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-05 15:07:35
Last updated 2026-08-06 14:35:47
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.