Medium severity5.4NVD Advisory· Published Jun 9, 2026· Updated Jun 11, 2026
CVE-2026-34033
CVE-2026-34033
Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/09/3nvdMailing List
- lists.apache.org/thread/wrfd9blbfotfg479jr8vlwfx6pwr9sgjnvdMailing List
News mentions
1- Apache HTTP Server and Answer: 22 Vulnerabilities Disclosed, Including Critical FlawsVypr Intelligence · Jun 10, 2026