Home

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

PUBLISHED Reserved 2026-03-23 | Published 2026-06-09 | Updated 2026-06-09 | Assigner apache

Problem types

CWE-434 Unrestricted Upload of File with Dangerous Type

Product status

Default status
unaffected

Any version
affected

Credits

Andy Gill, ZephrSec Ltd reporter

References

www.openwall.com/lists/oss-security/2026/06/09/5

lists.apache.org/thread/3sgpx4cwsgpnt66xv3cqvtc8z4st1kbq vendor-advisory

cve.org (CVE-2026-33582)

nvd.nist.gov (CVE-2026-33582)

Download JSON