CVE-2026-33582
Received Received - Intake
Unrestricted File Upload in Apache Answer

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: Apache Software Foundation

Description
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-09
AI Q&A
2026-06-09
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
apache answer to 2.0.0 (exc)
apache answer 2.0.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in Apache Answer (up to version 2.0.0) involves the unrestricted upload of files with dangerous types. Specifically, a crafted TIFF image can trigger excessive memory allocation during image decoding. This flaw allows an authenticated user to cause the server process to crash.

Impact Analysis

The impact of this vulnerability is that an authenticated user can cause the server process to crash by uploading a specially crafted TIFF image. This can lead to denial of service, disrupting the availability of the affected server.

Mitigation Strategies

To mitigate this vulnerability, users are recommended to upgrade Apache Answer to version 2.0.1, which fixes the issue.

Detection Guidance

This vulnerability affects Apache Answer versions through 2.0.0 and is triggered by uploading specially crafted TIFF image files that cause excessive memory allocation during image decoding, leading to server crashes.

To detect if your system is vulnerable, first verify the version of Apache Answer running on your server.

  • Check the Apache Answer version by running: apache-answer --version (or the equivalent command for your installation)
  • Monitor server logs for crashes or Out-of-Memory errors related to image processing.
  • Inspect recent uploads for TIFF files, especially those uploaded by authenticated users.

There are no specific detection commands provided in the available resources, but monitoring for abnormal server crashes after TIFF uploads and verifying the software version are key steps.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33582. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart