Back

HIGH

Apache Answer: Denial of service via crafted Accept-Language header parsing

Published Aug 5, 2026

Description

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.1.

Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Aug 5, 2026
Updated Aug 6, 2026
Reserved May 25, 2026
CISA Vulnrichment
Updated Aug 6, 2026
NVD
Status Analyzed
Modified Aug 6, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner apache
Published Aug 5, 2026
Updated Aug 6, 2026
Exploited since n/a
EUVD-2026-53396