Junglewise Threat Intelligence

CVE-2026-34031: Apache Answer unrestricted upload in profile image URLs

CVE-2026-34031 · Severity: medium · CVSS 6.5 · Published 2026-06-09

Technologies: github.com/apache/answer (Go), Apache Software Foundation Answer, github.com/apache/incubator-answer (Go). Vendors: Go, Apache Software Foundation, Apache.

Executive brief

Apache Answer, a Q&A platform, contains a vulnerability where it fails to properly validate user-supplied image URLs for profile avatars. This allows an attacker to embed arbitrary external content, which can be used to track users or trigger unintended requests to third-party servers when a user views the affected profile. Organizations should update to version 2.0.1 to prevent potential privacy leaks and unauthorized tracking of their users.

Technical details

A vulnerability classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) exists in Apache Answer through version 2.0.0. The application fails to sufficiently validate URLs provided for custom profile avatars, allowing the embedding of arbitrary external content. An unauthenticated remote attacker can exploit this to perform tracking of users via third-party servers or trigger unintended external requests. The fix, introduced in version 2.0.1, enhances avatar validation by adding checks for custom avatar URLs and improving image decoding checks for standard formats like JPEG, PNG, and GIF.

Affected products

  • Apache Answer through 2.0.0

Timeline

  • 2026-05-29: patched: Version 2.0.1 released
  • 2026-06-09: disclosed: Initial advisory publication
  • 2026-06-09: advisory: GitHub and NVD advisories published

References

Related threats