A AegiFlow
MEDIUMCVSS 6.5EPSS 0.4%

CVE-2026-34031

CVE-2026-34031 updated by NVD

Published
2026-06-09
Modified
2026-07-31
EPSS percentile
33%
Sources
github-advisory, nvd

Summary

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/apache/incubator-answer1.7.2-0.20260511040518-11091244f64e

Remediation: Upgrade to 1.7.2-0.20260511040518-11091244f64e or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.