VulnerabilityAnalyzed
CVE-2026-33582
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
MEDIUM 6.5EPSS 0.48%
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- apache/answer
- Source
- security@apache.org
References
- https://lists.apache.org/thread/3sgpx4cwsgpnt66xv3cqvtc8z4st1kbqMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/06/09/5Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.