---
id: CVE-2026-34031
aliases:
  - GHSA-x4f6-mqg6-28xx
title: >-
  Apache Answer has an Unrestricted Upload of File with Dangerous Type
  vulnerability
summary: >-
  Apache Answer has an Unrestricted Upload of File with Dangerous Type
  vulnerability
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
vendor: apache
product: github.com/apache/incubator-answer
ecosystem: go
affected:
  - github.com/apache/incubator-answer < 1.7.2-0.20260511040518-11091244f64e
patched:
  - github.com/apache/incubator-answer 1.7.2-0.20260511040518-11091244f64e
published: '2026-06-09'
updated: '2026-07-31'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-x4f6-mqg6-28xx'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34031'
  - url: >-
      https://github.com/apache/answer/commit/11091244f64e5a7e472edcd477c1ff4124eca7c3
  - url: 'https://github.com/apache/answer'
  - url: 'https://github.com/apache/answer/releases/tag/v2.0.1'
  - url: 'https://lists.apache.org/thread/rwtxy39t54to9kv3dqtbjsbdpyk4jkd2'
  - url: 'http://www.openwall.com/lists/oss-security/2026/06/09/4'
tags:
  - osv
  - go
epss: 0.00637
epssPercentile: 0.4832
ingestedAt: '2026-07-31T19:10:07.902Z'
---

## Overview

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.

## Affected packages

- `github.com/apache/incubator-answer < 1.7.2-0.20260511040518-11091244f64e`

## Remediation

Upgrade to a patched release:

- `github.com/apache/incubator-answer 1.7.2-0.20260511040518-11091244f64e`
