Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
Apache HTTP Server: Improper Input Validation Causing Local DoS
CVE-2025-48644
ASB-A-449181366
Summary
The Apache HTTP Server is vulnerable to a denial of service attack that can be triggered by malicious input, potentially disrupting website availability. This vulnerability does not require user interaction or elevated privileges to exploit. To mitigate this risk, update the Apache HTTP Server to the latest version.
What to do
- Update google platform/frameworks/base to version 16-qpr2-next:2026-03-01.
- Update google platform/frameworks/base to version 15:2026-03-01.
- Update google platform/frameworks/base to version 16:2026-03-01.
- Update google platform/frameworks/base to version 16-qpr2:2026-03-01.
- Update google platform/frameworks/base to version 14:2026-03-01.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| android | 14.0 | – | |
| android | 15.0 | – | |
| android | 16.0 | – | |
| android | 16.0 | – | |
| android | 16.0 | – | |
| android | 16.0 | – | |
| platform/frameworks/base | > 16-qpr2-next:0 , <= 16-qpr2-next:2026-03-01 | 16-qpr2-next:2026-03-01 | |
| platform/frameworks/base | > 15:0 , <= 15:2026-03-01 | 15:2026-03-01 | |
| platform/frameworks/base | > 16:0 , <= 16:2026-03-01 | 16:2026-03-01 | |
| platform/frameworks/base | > 16-qpr2:0 , <= 16-qpr2:2026-03-01 | 16-qpr2:2026-03-01 | |
| platform/frameworks/base | > 14:0 , <= 14:2026-03-01 | 14:2026-03-01 |
Original title
In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. ...
Original description
In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd CVSS3.1
5.5
Vulnerability type
CWE-20
Improper Input Validation
- https://source.android.com/docs/security/bulletin/2026/2026-03-01
- https://source.android.com/security/bulletin/2026-03-01 Vendor Advisory
- https://android.googlesource.com/platform/frameworks/base/+/2bca2265ff3e26b09f9b... Patch
- https://android.googlesource.com/platform/frameworks/base/+/a438ce172b441c8297ea... Patch
Published: 1 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026