216.73.217.22

CVE-2026-40477

· Published 17/04/2026 22:16 · Modified 17/04/2026 22:16

Labels: CVE-2026-40477 2026-04-17CVE-2026-40477CWE-917[email protected]

Essential information

Published
17/04/2026 22:16
Modified
17/04/2026 22:16
Author
Creator
CVSS
9.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached from within a template. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
thymeleaf / thymeleaf cpe:2.3:a:thymeleaf:thymeleaf:<3.1.4.RELEASE:*:*:*:*:*:*:*

References