Junglewise Threat Intelligence

CVE-2026-34033: Apache Answer XSS in notification emails

CVE-2026-34033 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Technologies: github.com/apache/answer (Go), Apache Software Foundation Answer, github.com/apache/incubator-answer (Go). Vendors: Go, Apache Software Foundation, Apache.

Executive brief

Apache Answer, an open-source Q&A platform, is vulnerable to a security flaw where user-provided content is not properly cleaned before being included in notification emails. This allows an attacker with a standard user account to inject malicious code or formatting into emails sent to other users. Such an exploit could be used for phishing or to mislead users, potentially damaging the organization's reputation or leading to further account compromise.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Apache Answer versions up to and including 2.0.0. The root cause is the improper neutralization of script-related HTML tags (CWE-80) within the email notification component. An authenticated attacker can provide malicious input that is subsequently included in notification emails sent to other users without proper HTML escaping. When a recipient views the email in a client that renders HTML, the injected code may execute or alter the message's appearance. This vulnerability is fixed in version 2.0.1 by implementing proper escaping of dynamic content in email templates.

Affected products

  • Apache Answer through 2.0.0

Timeline

  • 2026-05-29: patched: Version 2.0.1 released
  • 2026-06-09: disclosed: Public advisory published

References

Related threats