Input validation error in Apache Answer - CVE-2026-34031
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper validation of user-supplied URLs in custom avatar handling when processing profile image URLs. A remote user can supply a crafted external image URL to disclose sensitive information.
This can cause victims' browsers to make unintended requests to third-party servers, enabling external tracking.