github.com/apache/incubator-answer
A Q&A platform software for teams at any scales. Whether it's a community forum, help center, or knowledge management platform, you can always count on Apache Answer.
Activity
- Latest release
- 8mo ago
- Total releases
- 50
- Cadence
- ~14 days
- Last 12 months
- 3
Reach
- Stars
- 15.6k
Details
- First release
- Nov 01, 2022
| Version | Released | |
|---|---|---|
v1.7.1
minor
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.7.1
minor
Dependencies (47)
+ 39 more |
|
v1.7.1-RC2
pre
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.7.1-RC2
pre
Dependencies (47)
+ 39 more |
|
v1.7.1-RC1
pre
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.7.1-RC1
pre
Dependencies (47)
+ 39 more |
|
v1.6.0
minor
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (46)
+ 38 more |
|
v1.6.0-RC1
pre
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.6.0-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.5.1
patch
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.5.1
patch
Dependencies (46)
+ 38 more |
|
v1.5.0-RC1
pre
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.5.0-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.5.0
minor
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (46)
+ 38 more |
|
v1.4.5-RC1
pre
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.4.5-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.4.2
patch
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.4.2
patch
Dependencies (45)
+ 37 more |
|
v1.4.2-RC2
pre
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.4.2-RC2
pre
Dependencies (45)
+ 37 more |
|
v1.4.1
patch
7 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (45)
+ 37 more |
|
v1.4.1-RC2
pre
8 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.1-RC2
pre
Dependencies (45)
+ 37 more |
|
v1.4.1-RC1
pre
8 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.1-RC1
pre
Dependencies (45)
+ 37 more |
|
v1.4.0-RC1
pre
9 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.0-RC1
pre
Dependencies (45)
+ 37 more |
|
v1.4.0
minor
8 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (45)
+ 37 more |
|
v1.3.6-RC1
pre
11 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.6-RC1
pre
Dependencies (45)
+ 37 more |
|
v1.3.6
patch
9 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.6
patch
Dependencies (45)
+ 37 more |
|
v1.3.5-RC1
pre
11 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.5-RC1
pre
Dependencies (45)
+ 37 more |
|
v1.3.5
patch
11 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.5
patch
Dependencies (45)
+ 37 more |
|
v1.3.1-RC2
pre
11 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.1-RC2
pre
Dependencies (45)
+ 37 more |
|
v1.3.1
minor
11 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.1
minor
Dependencies (45)
+ 37 more |
|
v1.3.0-RC1
pre
12 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.0-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.2.5
patch
12 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.5
patch
Dependencies (46)
+ 38 more |
|
v1.2.5-RC2
pre
15 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.5-RC2
pre
Dependencies (46)
+ 38 more |
|
v1.2.5-RC1
pre
15 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.5-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.2.1-RC1
pre
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.1-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.2.1
patch
15 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (46)
+ 38 more |
|
v1.2.0-RC1
pre
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.0-RC1
pre
Dependencies (46)
+ 38 more |
|
v1.2.0
minor
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (45)
+ 37 more |
|
v1.1.3
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.3
patch
Dependencies (45)
+ 37 more |
|
v1.1.2
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (45)
+ 37 more |
|
v1.1.1
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (46)
+ 38 more |
|
v1.1.0
minor
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (47)
+ 39 more |
|
v1.1.0-beta.2
pre
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0-beta.2
pre
Dependencies (47)
+ 39 more |
|
v1.0.9
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.9
patch
Dependencies (46)
+ 38 more |
|
v1.1.0-beta.1
pre
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0-beta.1
pre
Dependencies (46)
+ 38 more |
|
v1.0.7
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.7
patch
Dependencies (45)
+ 37 more |
|
v1.0.6
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.6
patch
Dependencies (45)
+ 37 more |
|
v1.0.5
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.5
patch
Dependencies (45)
+ 37 more |
|
v1.0.4
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.4
patch
Dependencies (44)
+ 36 more |
|
v1.0.3
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.3
patch
Dependencies (43)
+ 35 more |
|
v1.0.1
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.1
patch
Dependencies (43)
+ 35 more |
|
v1.0.0
major
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (42)
+ 34 more |
|
v0.5.0
minor
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (37)
+ 29 more |
|
v0.4.2
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.2
patch
Dependencies (37)
+ 29 more |
|
v0.4.1
patch
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.1
patch
Dependencies (37)
+ 29 more |
|
v0.4.0
minor
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (37)
+ 29 more |
|
v0.3.0
minor
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (37)
+ 29 more |
|
v0.2.0
initial
16 CVEs
CVE-2026-25700
GO-2026-6249
GHSA-4gw2-vg4x-7p29
Aug 18, 2026
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/apache/answer before v2.0.1; github.com/apache/incubator-answer before v2.0.1. References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34031
GHSA-x4f6-mqg6-28xx
GO-2026-6154
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260511040518-11091244f64e
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34033
GHSA-6qwm-5fm9-cvjx
GO-2026-6151
Jun 09, 2026
Apache Answer vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509080709-d1a4092c61cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25688
GHSA-hmr2-99jm-8x45
GO-2026-6147
Jun 09, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260525024654-2746bf5b455f
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-34905
GHSA-85r2-pvg8-89r9
GO-2026-6152
Jun 09, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260509071350-11c80384f13a
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25699
GHSA-w754-5646-xq9j
GO-2026-6148
Jun 09, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260206073245-92994b49976b
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33582
GHSA-v553-g2w6-295p
GO-2026-6153
Jun 09, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Fixed in
1.7.2-0.20260325113131-cfc3e54f30cc
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2024-45719
GO-2024-3287
GHSA-mr95-vfcf-fx9p
Nov 27, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Apache Answer: Predictable Authorization Token Using UUIDv1 in github.com/apache/incubator-answer Fixed in
1.4.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-40761
GO-2024-3158
GHSA-48cr-j2cx-mcr8
Sep 26, 2024
Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Apache Answer: Avatar URL leaked user email addresses in github.com/apache/incubator-answer Fixed in
1.4.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41890
GO-2024-3064
GHSA-gvpv-r32v-9737
Aug 13, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Apache Answer: The link to reset the user's password will remain valid after sending a new link in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41888
GO-2024-3065
GHSA-v3x9-wrq5-868j
Aug 13, 2024
Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Apache Answer: The link for resetting user password is not Single-Use in github.com/apache/incubator-answer Fixed in
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-49619
GO-2024-2457
GHSA-f899-4mr4-fqpv
Jun 28, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-26578
GO-2024-2580
GHSA-9q24-hwmc-797x
Jun 04, 2024
Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Apache Answer Race Condition vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-23349
GO-2024-2578
GHSA-8pf2-qj4v-fj64
Jun 04, 2024
Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Apache Answer Cross-site Scripting vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-22393
GO-2024-2579
GHSA-rmqp-mvv2-54c6
Jun 04, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/incubator-answer Fixed in
1.2.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-29217
GO-2024-2743
GHSA-cvqr-mwh6-2vc6
Apr 26, 2024
XSS vulnerability via personal website in github.com/apache/incubator-answer XSS vulnerability via personal website in github.com/apache/incubator-answer Fixed in
1.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.2.0
initial
Dependencies (35)
+ 27 more |