github.com/apache/answer
A Q&A platform software for teams at any scales. Whether it's a community forum, help center, or knowledge management platform, you can always count on Apache Answer.
Activity
- Latest release
- 8mo ago
- Total releases
- 55
- Cadence
- ~14 days
- Last 12 months
- 5
Reach
- Stars
- 15.6k
Details
- First release
- Nov 01, 2022
| Version | Released | |
|---|---|---|
v1.7.1-RC2
pre
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.7.1-RC2
pre
Dependencies (47)
+ 39 more |
|
v1.7.1
minor
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.7.1
minor
Dependencies (47)
+ 39 more |
|
v1.7.1-RC1
pre
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.7.1-RC1
pre
Dependencies (47)
+ 39 more |
|
v1.7.0
minor
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (47)
+ 39 more |
|
v1.7.0-RC1
pre
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.7.0-RC1
pre
Dependencies (47)
+ 39 more |
|
v1.6.0
minor
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (46)
+ 38 more |
|
v1.6.0-RC1
pre
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.6.0-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.5.1-RC1
pre
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.5.1-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.5.1
patch
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.5.1
patch
Dependencies (46)
+ 38 more |
|
v1.5.0-RC1
pre
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.5.0-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.5.0
minor
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (46)
+ 38 more |
|
v1.4.5
patch
8 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev |
v1.4.5
patch
Dependencies (46)
+ 38 more |
|
v1.4.5-RC1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.5-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.4.2-RC2
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.2-RC2
pre
Dependencies (45)
+ 37 more |
|
v1.4.2
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.2
patch
Dependencies (45)
+ 37 more |
|
v1.4.2-RC1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.2-RC1
pre
Dependencies (45)
+ 37 more |
|
v1.4.1
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (45)
+ 37 more |
|
v1.4.1-RC2
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.1-RC2
pre
Dependencies (45)
+ 37 more |
|
v1.4.1-RC1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.1-RC1
pre
Dependencies (45)
+ 37 more |
|
v1.4.0-RC1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.0-RC1
pre
Dependencies (45)
+ 37 more |
|
v1.4.0
minor
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (45)
+ 37 more |
|
v1.3.6
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.6
patch
Dependencies (45)
+ 37 more |
|
v1.3.6-RC1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.6-RC1
pre
Dependencies (45)
+ 37 more |
|
v1.3.5
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.5
patch
Dependencies (45)
+ 37 more |
|
v1.3.5-RC1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.5-RC1
pre
Dependencies (45)
+ 37 more |
|
v1.3.1
minor
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.1
minor
Dependencies (45)
+ 37 more |
|
v1.3.1-RC2
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.1-RC2
pre
Dependencies (45)
+ 37 more |
|
v1.3.0-RC1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.0-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.2.5
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.5
patch
Dependencies (46)
+ 38 more |
|
v1.2.5-RC2
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.5-RC2
pre
Dependencies (46)
+ 38 more |
|
v1.2.5-RC1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.5-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.2.1-RC1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.1-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.2.1
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (46)
+ 38 more |
|
v1.2.0
minor
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (46)
+ 38 more |
|
v1.2.0-RC1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.0-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.1.3
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.3
patch
Dependencies (45)
+ 37 more |
|
v1.1.2
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (45)
+ 37 more |
|
v1.1.1
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (46)
+ 38 more |
|
v1.1.0
minor
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (47)
+ 39 more |
|
v1.1.0-beta.2
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0-beta.2
pre
Dependencies (47)
+ 39 more |
|
v1.0.9
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.9
patch
Dependencies (46)
+ 38 more |
|
v1.1.0-beta.1
pre
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0-beta.1
pre
Dependencies (46)
+ 38 more |
|
v1.0.7
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.7
patch
Dependencies (45)
+ 37 more |
|
v1.0.6
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.6
patch
Dependencies (45)
+ 37 more |
|
v1.0.5
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.5
patch
Dependencies (45)
+ 37 more |
|
v1.0.4
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.4
patch
Dependencies (44)
+ 36 more |
|
v1.0.3
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.3
patch
Dependencies (43)
+ 35 more |
|
v1.0.1
patch
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.1
patch
Dependencies (43)
+ 35 more |
|
v1.0.0
major
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (42)
+ 34 more |
|
v0.5.0
minor
9 CVEs
CVE-2026-25699
GO-2026-6148
GHSA-w754-5646-xq9j
Aug 18, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GO-2026-6152
GHSA-85r2-pvg8-89r9
Aug 18, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GO-2026-6151
GHSA-6qwm-5fm9-cvjx
Aug 18, 2026
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GO-2026-6153
GHSA-v553-g2w6-295p
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GO-2026-6154
GHSA-x4f6-mqg6-28xx
Aug 18, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GO-2026-6147
GHSA-hmr2-99jm-8x45
Aug 18, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-24735
GO-2026-4421
GHSA-5w5r-8xc6-2xhw
Feb 05, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.0. References Updated Feb 05, 2026 · Source: OSV.dev
CVE-2025-29868
GO-2025-3587
GHSA-wqcc-mfhw-53pc
Apr 02, 2025
Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Apache Answer User Using External Images Potentially Discloses User Information in github.com/apache/answer Fixed in
1.4.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (37)
+ 29 more |