CVE-2026-33582
Analyzed Analyzed - Analysis Complete

Unrestricted File Upload in Apache Answer

Vulnerability report for CVE-2026-33582, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-09

Last updated on: 2026-06-10

Assigner: Apache Software Foundation

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-09
Last Modified
2026-06-10
Generated
2026-06-29
AI Q&A
2026-06-09
EPSS Evaluated
2026-06-28
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache answer to 2.0.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Apache Answer (up to version 2.0.0) involves the unrestricted upload of files with dangerous types. Specifically, a crafted TIFF image can trigger excessive memory allocation during image decoding. This flaw allows an authenticated user to cause the server process to crash.

Impact Analysis

The impact of this vulnerability is that an authenticated user can cause the server process to crash by uploading a specially crafted TIFF image. This can lead to denial of service, disrupting the availability of the affected server.

Mitigation Strategies

To mitigate this vulnerability, users are recommended to upgrade Apache Answer to version 2.0.1, which fixes the issue.

Detection Guidance

This vulnerability affects Apache Answer versions through 2.0.0 and is triggered by uploading specially crafted TIFF image files that cause excessive memory allocation during image decoding, leading to server crashes.

To detect if your system is vulnerable, first verify the version of Apache Answer running on your server.

  • Check the Apache Answer version by running: apache-answer --version (or the equivalent command for your installation)
  • Monitor server logs for crashes or Out-of-Memory errors related to image processing.
  • Inspect recent uploads for TIFF files, especially those uploaded by authenticated users.

There are no specific detection commands provided in the available resources, but monitoring for abnormal server crashes after TIFF uploads and verifying the software version are key steps.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33582. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart