What is CVE-2026-48834?
CVE-2026-48834: An improper handling of length parameter inconsistency vulnerability in Apache Answer (through version 2.0.1) allows unauthenticated attackers to cause denial of service (DoS). A specially crafted Accept-Language header can trigger excessive CPU consumption during parsing. Users are urged to update immediately.
Azərbaycanca: CVE-2026-48834: Apache Answer platformasında (2.0.1 versiyasına qədər) 'Length Parameter Inconsistency' zəifliyi aşkar edilib. Təsdiqlənməmiş hücumçular xüsusi hazırlanmış Accept-Language başlığı vasitəsilə həddindən artıq CPU istehlakına səbəb olaraq xidmət dayandırılması (DoS) həyata keçirə bilərlər. İstifadəçilərə dərhal proqram təminatını yeniləmək tövsiyə olunub.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which versions of Apache Answer are affected by CVE-2026-48834?
The vulnerability affects Apache Answer versions up to and including 2.0.1.
What can an attacker achieve by exploiting CVE-2026-48834?
An unauthenticated attacker can cause denial of service (DoS) by sending a specially crafted Accept-Language header that triggers excessive CPU consumption.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.