As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-84939: Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks
Apache FreeMarker versions 2.2.0 through 2.3.34 contain a path traversal vulnerability in the template loading mechanism that can be exploited through a malformed locale parameter. Version 2.3.35 and later address the issue. Both the standard freemarker and freemarker-gae packages are affected.
Why it matters: Teams using FreeMarker for template processing should update to version 2.3.35 or later immediately if they accept user-controlled locale input, as attackers could access arbitrary files on the system.
- Source published
- First seen by Cybersecurity Tracker