Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84939— Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks

Quick assessment

Affected
Apache Software Foundation Apache FreeMarker
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是这段漏洞描述的中文翻译: Apache FreeMarker 模板加载机制中存在路径遍历漏洞。如果攻击者能够向 FreeMarker 指定任意格式错误的 locale(区域设置)标识符,且启用了本地化查找配置(该配置默认启用),则可能触发此漏洞。 受影响版本: 该问题影响 Apache FreeMarker 2.2.0 至 2.3.34 版本。 修复与缓解措施: 建议用户升级至 2.3.35 版本。对于较早版本,也可通过禁用本地化查找功能来缓解此漏洞。 补充说明: 需要注意的是,即使在使用受影响版本时,可加载

AI Predicted 6.5 Difficulty: Moderate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84939

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks
Source: CVE Program / CVE List V5
Vulnerability Description
Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue affects Apache FreeMarker from 2.2.0 through 2.3.34. Users are recommended to upgrade to version 2.3.35. Disabling localized lookup in previous versions also mitigates this. Note that even in versions affected by this vulnerability, the files that can be loaded remain restricted by the TemplateLoader that FreeMarker is configured to use. In particular, FileTemplateLoader prevents attempts to traverse outside the baseDir specified in its constructor. Other TemplateLoader implementations may allow access outside their designated base directory, but they are still constrained by the underlying storage mechanism—for example, a loader wrapping a Java class loader can only access resources that the class loader can load, while one wrapping a web application context can only access resources available through that context.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
相对路径遍历
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache FreeMarker 2.2.0 ~ 2.3.34 -
Apache Software Foundation Apache FreeMarker 2.2.0 ~ 2.3.34 -

II. Public POCs for CVE-2026-84939

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84939

登录查看更多情报信息。

Mailing List Discussions for CVE-2026-84939 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-10 · 11 CVEs total

CVE-2026-80354 Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secr
CVE-2026-80351 Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod
CVE-2026-80352 Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author appl
CVE-2026-49362 Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler A
CVE-2026-49363 Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE
CVE-2026-49364 Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Auth
CVE-2026-57822 Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserializatio
CVE-2026-57967 Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session r
CVE-2026-67593 Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-auth
CVE-2026-75880 Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to

IV. Related Vulnerabilities

V. Comments for CVE-2026-84939

No comments yet


Leave a comment