Medium severity6.5NVD Advisory· Published Jun 9, 2026· Updated Jun 10, 2026
CVE-2026-34031
CVE-2026-34031
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/apache/incubator-answerGo | < 1.7.2-0.20260511040518-11091244f64e | 1.7.2-0.20260511040518-11091244f64e |
Affected products
2Patches
Vulnerability mechanics
References
6- www.openwall.com/lists/oss-security/2026/06/09/4nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-x4f6-mqg6-28xxghsaADVISORY
- lists.apache.org/thread/rwtxy39t54to9kv3dqtbjsbdpyk4jkd2nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-34031ghsaADVISORY
- github.com/apache/answer/commit/11091244f64e5a7e472edcd477c1ff4124eca7c3ghsaWEB
- github.com/apache/answer/releases/tag/v2.0.1ghsaWEB
News mentions
1- Apache HTTP Server and Answer: 22 Vulnerabilities Disclosed, Including Critical FlawsVypr Intelligence · Jun 10, 2026