CVE-2026-40477
Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached from within a template. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.
- CVSS 3.1
- 9.0 CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-917, CWE-1336
- Affected
- thymeleaf/thymeleaf
- Source
- security-advisories@github.com
References
- https://github.com/thymeleaf/thymeleaf/security/advisories/GHSA-r4v4-5mwr-2fwrVendor Advisory
- https://access.redhat.com/errata/RHSA-2026:21772
- https://access.redhat.com/security/cve/CVE-2026-40477
- https://bugzilla.redhat.com/show_bug.cgi?id=2459344
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40477.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.