Medium severity5.4NVD Advisory· Published Jun 9, 2026· Updated Jun 11, 2026
CVE-2026-34033
CVE-2026-34033
Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/apache/incubator-answerGo | < 1.7.2-0.20260509080709-d1a4092c61cc | 1.7.2-0.20260509080709-d1a4092c61cc |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-6qwm-5fm9-cvjxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-34033ghsaADVISORY
- www.openwall.com/lists/oss-security/2026/06/09/3nvdMailing ListWEB
- github.com/apache/answer/commit/d1a4092c61ccd41988d1033fce47eb513adb433eghsaWEB
- github.com/apache/answer/releases/tag/v2.0.1ghsaWEB
- lists.apache.org/thread/wrfd9blbfotfg479jr8vlwfx6pwr9sgjnvdMailing ListWEB
News mentions
1- Apache HTTP Server and Answer: 22 Vulnerabilities Disclosed, Including Critical FlawsVypr Intelligence · Jun 10, 2026