github.com/apache/answer
Go9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/apache/answerpage 1 of 1
- CVE-2025-29868MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.4.52025-04-01
Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the ima…
- CVE-2026-24735HIGHCVSS 7.5EG 7.5✓ Fixed in 2.0.02026-02-04
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly exposes full revision history for deleted cont…
- CVE-2026-25688MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.7.2-0.20260525024654-2746bf5b455f2026-06-09
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious sc…
- CVE-2026-25699MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.7.2-0.20260206073245-92994b49976b2026-06-09
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated u…
- CVE-2026-25700HIGHCVSS 7.2EG 7.2✓ Fixed in 2.0.12026-06-10
Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended,…
- CVE-2026-33582MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.7.2-0.20260325113131-cfc3e54f30cc2026-06-09
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authentica…
- CVE-2026-34031MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.7.2-0.20260511040518-11091244f64e2026-06-09
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be…
- CVE-2026-34033MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.7.2-0.20260509080709-d1a4092c61cc2026-06-09
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escap…
- CVE-2026-34905MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.7.2-0.20260509071350-11c80384f13a2026-06-09
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowi…
Check whether github.com/apache/answer is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/apache/answer CVEs against the assets you own.
Start Free Scan →