Source: libfreemarker-java Version: 2.3.32-2.1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for libfreemarker-java. CVE-2026-84939[0]: | Path traversal vulnerability in Apache FreeMarker template loading | mechanism, if the attacker can specify an arbitrary malformed locale | identifier to FreeMarker, and the localized lookup configuration | setting is enabled (it's by default enabled). This issue affects | Apache FreeMarker from 2.2.0 through 2.3.34. Users are recommended | to upgrade to version 2.3.35. Disabling localized lookup in previous | versions also mitigates this. Note that even in versions affected | by this vulnerability, the files that can be loaded remain | restricted by the TemplateLoader that FreeMarker is configured to | use. In particular, FileTemplateLoader prevents attempts to traverse | outside the baseDir specified in its constructor. Other | TemplateLoader implementations may allow access outside their | designated base directory, but they are still constrained by the | underlying storage mechanism—for example, a loader wrapping a Java | class loader can only access resources that the class loader can | load, while one wrapping a web application context can only access | resources available through that context. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-84939 https://www.cve.org/CVERecord?id=CVE-2026-84939 [1] https://lists.apache.org/thread/hrd7o2ylwkkswdyhyzllgqt0f80kyd5y Regards, Salvatore

