CVE-2026-33582
MEDIUMApache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error
Title source: cnaDescription
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/3sgpx4cwsgpnt66xv3cqvtc8z4st1kbq
Scores
CVSS v3
6.5
EPSS
0.0042
EPSS Percentile
33.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-434
Status
published
Products (2)
apache/answer
< 2.0.1
Apache Software Foundation/Apache Answer
< 2.0.0
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026