GHSA-x4f6-mqg6-28xxMediumCVSS 6.5
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
🔗 CVE IDs covered (1)
📋 Description
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
🎯 Affected products1
- go/github.com/apache/incubator-answer:< 1.7.2-0.20260511040518-11091244f64e
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-34031
- https://lists.apache.org/thread/rwtxy39t54to9kv3dqtbjsbdpyk4jkd2
- http://www.openwall.com/lists/oss-security/2026/06/09/4
- https://github.com/apache/answer/commit/11091244f64e5a7e472edcd477c1ff4124eca7c3
- https://github.com/apache/answer/releases/tag/v2.0.1
- https://github.com/advisories/GHSA-x4f6-mqg6-28xx