MEDIUM 6.5
GHSA-x4f6-mqg6-28xx
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Quick fix
GHSA-x4f6-mqg6-28xx — github.com/apache/incubator-answer: upgrade to the fixed version with the command below.
go get github.com/apache/incubator-answer@v1.7.2-0.20260511040518-11091244f64e Details
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/apache/incubator-answer
Introduced in:
0 Fixed in: 1.7.2-0.20260511040518-11091244f64e Fix
go get github.com/apache/incubator-answer@v1.7.2-0.20260511040518-11091244f64e References
- https://nvd.nist.gov/vuln/detail/CVE-2026-34031 [ADVISORY]
- https://github.com/apache/answer/commit/11091244f64e5a7e472edcd477c1ff4124eca7c3 [WEB]
- https://github.com/apache/answer [PACKAGE]
- https://github.com/apache/answer/releases/tag/v2.0.1 [WEB]
- https://lists.apache.org/thread/rwtxy39t54to9kv3dqtbjsbdpyk4jkd2 [WEB]
- http://www.openwall.com/lists/oss-security/2026/06/09/4 [WEB]