{"id":"CVE-2024-22393","aliases":["GHSA-rmqp-mvv2-54c6","GO-2024-2579"],"url":"https://o3.security/vulnerability/CVE-2024-22393","summary":"Apache Answer: Pixel Flood Attack by uploading the large pixel file","details":"Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer through 1.2.1.\n\nPixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content.\n\nUsers are recommended to upgrade to version 1.2.5, which fixes the issue.","published":"2024-02-22T09:51:43.432Z","modified":"2026-08-12T03:51:45.387953386Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"},"epss":{"score":0.02459,"percentile":0.8319,"asOf":"2026-08-29"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/apache/incubator-answer","fixedVersion":"1.2.5"}],"fix":null,"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/02/22/1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/22xxx/CVE-2024-22393.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/f58l6dr4r74hl6o71gn47kmn44vw12cv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22393"},{"type":"PACKAGE","url":"https://github.com/apache/incubator-answer"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:45.387953386Z"}}