Unrestricted File Upload Vulnerability in Apache Answer by Apache
CVE-2026-34031
6.5MEDIUM
What is CVE-2026-34031?
The unrestricted file upload vulnerability in Apache Answer allows attackers to exploit insufficient validation of user-supplied image URLs. This flaw enables arbitrary external content to be embedded as profile images, posing risks of unintended external requests and potential tracking by third-party servers. Users are highly encouraged to update to version 2.0.1 to mitigate these security risks.
Affected Version(s)
Apache Answer 0 <= 2.0.0