
🚨 CVE-2026-40477: Improper restriction of the scop... Thymeleaf's object scope restrictions are paper-thin - SSTI bypass via unvalidated input hits 9.1 CVSS, time to audit t... https://zerodaysignal.com/vulnerability/CVE-2026-40477 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
A new high‑severity SSTI vulnerability (CVE‑2026‑40477) in Thymeleaf has been disclosed, citing a CVSS score of 9.1 and unvalidated input as the attack vector, but no PoC, exploit code, patch, or evidence of active exploitation is provided.



