CVE-2026-34031: Apache Answer: The custom avatar was not properly validated
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Answerto a version that resolves this vulnerability.Fixed in 2.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34031?
CVE-2026-34031 has a medium severity rating of 6.5 based on the CVSS 3.1 scoring system.
What is the risk associated with CVE-2026-34031?
CVE-2026-34031 has a risk rating of 42, indicating a significant potential impact if exploited.
How do I fix CVE-2026-34031?
To fix CVE-2026-34031, ensure that user-supplied image URLs are properly validated before allowing uploads.
What impact does CVE-2026-34031 have on users?
CVE-2026-34031 could expose users to unintended consequences by allowing malicious content to be embedded as profile images.
Which versions of Apache Answer are affected by CVE-2026-34031?
CVE-2026-34031 affects all versions of Apache Answer up to 2.0.0.