#1147516 libfreemarker-java: CVE-2026-84939

Package:
src:libfreemarker-java
Source:
src:libfreemarker-java
Submitter:
Salvatore Bonaccorso
Date:
2026-09-12 15:11:02 UTC
Severity:
normal
Tags:
#1147516#5
Date:
2026-09-12 15:10:21 UTC
From:
To:
Hi,

The following vulnerability was published for libfreemarker-java.

CVE-2026-84939[0]:
| Path traversal vulnerability in Apache FreeMarker template loading
| mechanism, if the attacker can specify an arbitrary malformed locale
| identifier to FreeMarker, and the localized lookup configuration
| setting is enabled (it's by default enabled).  This issue affects
| Apache FreeMarker from 2.2.0 through 2.3.34.  Users are recommended
| to upgrade to version 2.3.35. Disabling localized lookup in previous
| versions also mitigates this.  Note that even in versions affected
| by this vulnerability, the files that can be loaded remain
| restricted by the TemplateLoader that FreeMarker is configured to
| use. In particular, FileTemplateLoader prevents attempts to traverse
| outside the baseDir specified in its constructor. Other
| TemplateLoader implementations may allow access outside their
| designated base directory, but they are still constrained by the
| underlying storage mechanism—for example, a loader wrapping a Java
| class loader can only access resources that the class loader can
| load, while one wrapping a web application context can only access
| resources available through that context.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-84939
https://www.cve.org/CVERecord?id=CVE-2026-84939
[1] https://lists.apache.org/thread/hrd7o2ylwkkswdyhyzllgqt0f80kyd5y

Regards,
Salvatore