CVE-2026-34031

CVE-2026-34031: Apache Answer: The custom avatar was not properly validated

Vendor Apache Software Foundation
Product Apache Answer
Weakness CWE-434 · Unrestricted file upload
Published June 9, 2026
Last update June 9, 2026

CVSS base score

What the vulnerability does

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Key dates

Disclosure timeline

June 9, 2026 CVE published
June 9, 2026 Record updated