CVE-2026-34031 PUBLISHED

Apache Answer: The custom avatar was not properly validated

Assigner: apache
Reserved: 25.03.2026 Published: 09.06.2026 Updated: 09.06.2026

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Answer
Versions Default: unaffected
  • affected from 0 to 2.0.0 (incl.)

Credits

  • Reimar Fritz reporter

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE