oss-sec mailing list archives

CVE-2026-33582: Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error


From: Enxin Xie <linkinstar () apache org>
Date: Tue, 09 Jun 2026 05:15:39 +0000

Severity: important 

Affected versions:

- Apache Answer through 2.0.0

Description:

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to 
cause the server process to crash.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Credit:

Andy Gill, ZephrSec Ltd (reporter)

References:

https://answer.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-33582


Current thread: