CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-84939: Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6712

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-84939: Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks

Apache FreeMarker versions 2.2.0 through 2.3.34 contain a path traversal vulnerability in the template loading mechanism that can be exploited through a malformed locale parameter. Version 2.3.35 and later address the issue. Both the standard freemarker and freemarker-gae packages are affected.

Why it matters: Teams using FreeMarker for template processing should update to version 2.3.35 or later immediately if they accept user-controlled locale input, as attackers could access arbitrary files on the system.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary