MEDIUM 6.5
GHSA-v553-g2w6-295p
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Quick fix
GHSA-v553-g2w6-295p — github.com/apache/incubator-answer: upgrade to the fixed version with the command below.
go get github.com/apache/incubator-answer@v1.7.2-0.20260325113131-cfc3e54f30cc Details
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/apache/incubator-answer
Introduced in:
0 Fixed in: 1.7.2-0.20260325113131-cfc3e54f30cc Fix
go get github.com/apache/incubator-answer@v1.7.2-0.20260325113131-cfc3e54f30cc References
- https://nvd.nist.gov/vuln/detail/CVE-2026-33582 [ADVISORY]
- https://github.com/apache/answer/commit/cfc3e54f30cc5e01afb7110ecc1da9152d0a3a41 [WEB]
- https://github.com/apache/answer [PACKAGE]
- https://github.com/apache/answer/releases/tag/v2.0.1 [WEB]
- https://lists.apache.org/thread/3sgpx4cwsgpnt66xv3cqvtc8z4st1kbq [WEB]
- http://www.openwall.com/lists/oss-security/2026/06/09/5 [WEB]