Improper Handling of Length Parameter Inconsistency in Apache Answer - CVE-2026-48834
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of length parameter inconsistency in Accept-Language header parsing when handling a specially crafted Accept-Language header. A remote attacker can send a specially crafted Accept-Language header to cause a denial of service.
The issue triggers excessive CPU consumption during parsing.