CVE-2026-33582

CVE-2026-33582: Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error

Vendor Apache Software Foundation
Product Apache Answer
Weakness CWE-434 · Unrestricted file upload
Published June 9, 2026
Last update June 9, 2026

CVSS base score

What the vulnerability does

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Key dates

Disclosure timeline

June 9, 2026 CVE published
June 9, 2026 Record updated