https://seclists.org/oss-sec/2026/q2/851: CVE-2026-33582: Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error
Published Jun 9, 2026
·Updated
Affected Software
1 affected component
Apache Answer<=2.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-33582?
The severity of CVE-2026-33582 is classified as important.
2
What versions of Apache Answer are affected by CVE-2026-33582?
CVE-2026-33582 affects Apache Answer versions through 2.0.0.
3
What type of vulnerability is CVE-2026-33582?
CVE-2026-33582 is an Unrestricted Upload of File with Dangerous Type vulnerability.
4
What happens when exploiting CVE-2026-33582?
Exploiting CVE-2026-33582 can cause an Out-of-Memory error due to excessive memory allocation when decoding a crafted TIFF file.
5
How do I mitigate CVE-2026-33582?
To mitigate CVE-2026-33582, disable or restrict uploading of TIFF files in Apache Answer until a patch is applied.