Directory Traversal Affecting keycloak-fips-26.6 package, versions <26.6.7-r5


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.85% (57th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-KEYCLOAKFIPS266-20338289
  • published1 Oct 2026
  • disclosed10 Sept 2026

Introduced: 10 Sep 2026

NewCVE-2026-84939  (opens in a new tab)
CWE-23  (opens in a new tab)

How to fix?

Upgrade Chainguard keycloak-fips-26.6 to version 26.6.7-r5 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream keycloak-fips-26.6 package and not the keycloak-fips-26.6 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled).

This issue affects Apache FreeMarker from 2.2.0 through 2.3.34.

Users are recommended to upgrade to version 2.3.35. Disabling localized lookup in previous versions also mitigates this.

Note that even in versions affected by this vulnerability, the files that can be loaded remain restricted by the TemplateLoader that FreeMarker is configured to use. In particular, FileTemplateLoader prevents attempts to traverse outside the baseDir specified in its constructor. Other TemplateLoader implementations may allow access outside their designated base directory, but they are still constrained by the underlying storage mechanism—for example, a loader wrapping a Java class loader can only access resources that the class loader can load, while one wrapping a web application context can only access resources available through that context.

CVSS Base Scores

version 3.1