---
id: CVE-2026-33582
aliases:
  - GHSA-v553-g2w6-295p
title: >-
  Apache Answer has an Unrestricted Upload of File with Dangerous Type
  vulnerability
summary: >-
  Apache Answer has an Unrestricted Upload of File with Dangerous Type
  vulnerability
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
vendor: apache
product: github.com/apache/incubator-answer
ecosystem: go
affected:
  - github.com/apache/incubator-answer < 1.7.2-0.20260325113131-cfc3e54f30cc
patched:
  - github.com/apache/incubator-answer 1.7.2-0.20260325113131-cfc3e54f30cc
published: '2026-06-09'
updated: '2026-07-31'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-v553-g2w6-295p'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33582'
  - url: >-
      https://github.com/apache/answer/commit/cfc3e54f30cc5e01afb7110ecc1da9152d0a3a41
  - url: 'https://github.com/apache/answer'
  - url: 'https://github.com/apache/answer/releases/tag/v2.0.1'
  - url: 'https://lists.apache.org/thread/3sgpx4cwsgpnt66xv3cqvtc8z4st1kbq'
  - url: 'http://www.openwall.com/lists/oss-security/2026/06/09/5'
tags:
  - osv
  - go
epss: 0.00653
epssPercentile: 0.49045
ingestedAt: '2026-07-31T19:10:07.861Z'
---

## Overview

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.

## Affected packages

- `github.com/apache/incubator-answer < 1.7.2-0.20260325113131-cfc3e54f30cc`

## Remediation

Upgrade to a patched release:

- `github.com/apache/incubator-answer 1.7.2-0.20260325113131-cfc3e54f30cc`
