PT-2026-33215 · Thymeleaf · Thymeleaf

Published

2026-04-15

·

Updated

2026-04-30

·

CVE-2026-40478

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Thymeleaf versions prior to 3.1.4.RELEASE
Description A security bypass exists in the expression execution mechanisms. The library fails to properly neutralize specific syntax patterns, which allows for the execution of unauthorized expressions. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can achieve Server-Side Template Injection (SSTI), a flaw where an attacker injects malicious code into a template, potentially leading to code execution or data exposure.
Recommendations Update to version 3.1.4.RELEASE. Ensure applications do not pass unvalidated user input directly to the template engine.

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-05835
CVE-2026-40478
GHSA-XJW8-8C5C-9R79

Affected Products

Thymeleaf