{
  "from_raw": "Enxin Xie <linkinstar@apache.org>",
  "from": "Enxin Xie <li...@apache.org>",
  "gravatar": "e817dfc7223a5b6ab7ceaa4c3a08eb2a",
  "to": "an...@apache.org,\n de...@answer.apache.org",
  "subject": "CVE-2026-34031: Apache Answer: The custom avatar was not properly validated",
  "message-id": "<0ac456ee-0798-1120-2336-34ccefec1cd7@apache.org>",
  "mid": "t7p6oxh22m90o736cg1xmk4lwd1wdktt",
  "permalinks": [
    "t7p6oxh22m90o736cg1xmk4lwd1wdktt",
    "rbe50ef1f42952f4d26fff2199292a8bc826ae0d2014f1c1ce32a261d@<announce.apache.org>"
  ],
  "dbid": "7ed898087bfe0e07ec69da59b43c77241d1574952960f5d8227bcb61e5608a69",
  "cc": "de...@answer.apache.org",
  "epoch": 1780982103,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/06/09 05:15:03",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: moderate \n\nAffected versions:\n\n- Apache Answer through 2.0.0\n\nDescription:\n\nUnrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.0.\n\nThe server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers.\nUsers are recommended to upgrade to version 2.0.1, which fixes the issue.\n\nCredit:\n\nReimar Fritz (reporter)\n\nReferences:\n\nhttps://answer.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-34031\n\n",
  "body_short": "Severity: moderate \n\nAffected versions:\n\n- Apache Answer through 2.0.0\n\nDescription:\n\nUnrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: ",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2584,
  "id": "t7p6oxh22m90o736cg1xmk4lwd1wdktt"
}