https://seclists.org/oss-sec/2026/q2/849: CVE-2026-34033: Apache Answer: HTML Content Injection in Email
Published Jun 9, 2026
·Updated
Affected Software
1 affected component
Apache Answer<=2.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-34033?
The severity of CVE-2026-34033 is classified as important.
2
Which versions of Apache Answer are affected by CVE-2026-34033?
CVE-2026-34033 affects Apache Answer through version 2.0.0.
3
What type of vulnerability is CVE-2026-34033?
CVE-2026-34033 is an improper neutralization of script-related HTML tags in a web page, also known as basic XSS.
4
How can I mitigate CVE-2026-34033?
To mitigate CVE-2026-34033, upgrade to a later version of Apache Answer that is not affected.
5
What is the impact of CVE-2026-34033 on users?
The impact of CVE-2026-34033 includes the potential for HTML content injection in notification emails, which may lead to XSS attacks.