Cross-site scripting in Apache Answer - CVE-2026-34033
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to inject arbitrary HTML into notification emails sent to other users.
The vulnerability exists due to improper neutralization of script-related html tags in notification emails when including user-supplied content. A remote user can submit crafted content to inject arbitrary HTML into notification emails sent to other users.