CVE-2026-40477Disclosure(thymeleaf / thymeleaf)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch thymeleaf thymeleaf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached from within a template. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-917CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • thymeleaf

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-18); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
thymeleaf

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-16: 1Mentions · 2026-04-18: 2Mentions · 2026-04-20: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-20: 104-1604-1804-20
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-161
Disclosure1
2026-04-182
Disclosure1General1
2026-04-201
Disclosure1
Full discourse4 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40477: Improper restriction of the scop... Thymeleaf's object scope restrictions are paper-thin - SSTI bypass via unvalidated input hits 9.1 CVSS, time to audit t... https://zerodaysignal.com/vulnerability/CVE-2026-40477 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new high‑severity SSTI vulnerability (CVE‑2026‑40477) in Thymeleaf has been disclosed, citing a CVSS score of 9.1 and unvalidated input as the attack vector, but no PoC, exploit code, patch, or evidence of active exploitation is provided.

    00000117
    218 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40477 Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the e… https://www.cve.org/CVERecord?id=CVE-2026-40477

    Post summary

    The text merely announces a CVE with a brief mention of a security bypass, but provides no detailed information, PoC, exploit, patch, or active exploitation data.

    00000135
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40477 Server-Side Template Injection in Thymeleaf 3.1.3.RELEASE and Pri... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40477 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The text announces the discovery of a server‑side template injection flaw in Thymeleaf 3.1.3.RELEASE, providing the CVE identifier and a brief description, but no PoC, exploit, or patch details.

    0000066
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A scope restriction vulnerability (CVE-2026-40477) affects `Thymeleaf` expressions, potentially leading to unauthorized object access. Review `Thymeleaf` configurations and input validation processes to mitigate risk. #infosec #websecurity https://www.pulsepatch.io/posts/cve-2026-40477-thymeleaf-object-scope-restriction

    Post summary

    The tweet reports that CVE‑2026‑40477 is a scope‑restriction flaw in Thymeleaf capable of unauthorized object access and recommends reviewing configuration and input validation for mitigation.

    0000083
    12 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appthymeleafthymeleaf---

Explore more