PT-2026-33215 · Thymeleaf · Thymeleaf
Published
2026-04-15
·
Updated
2026-04-30
·
CVE-2026-40478
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Thymeleaf versions prior to 3.1.4.RELEASE
Description
A security bypass exists in the expression execution mechanisms. The library fails to properly neutralize specific syntax patterns, which allows for the execution of unauthorized expressions. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can achieve Server-Side Template Injection (SSTI), a flaw where an attacker injects malicious code into a template, potentially leading to code execution or data exposure.
Recommendations
Update to version 3.1.4.RELEASE.
Ensure applications do not pass unvalidated user input directly to the template engine.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Thymeleaf