CVE-2026-40478Disclosure(thymeleaf / thymeleaf)

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for thymeleaf thymeleaf systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of unauthorized expressions. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-917CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • thymeleaf

Threat summary

  • Public PoC and exploit tooling are both present
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 3 mentions (2026-04-16); latest day: 1
  • 10 total mentions across 7 days

Affected systems

Vendors
Products
thymeleaf

Deep dive

Activity timeline10 mentions / 7d
01223Mentions · 2026-04-16: 3Mentions · 2026-04-18: 2Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Mentions · 2026-04-29: 1Mentions · 2026-04-30: 1Mentions · 2026-06-30: 1PoC Mentioned / Linked · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-30: 1Exploit Tool / Code · 2026-04-30: 1Technical Details · 2026-04-16: 3Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-30: 1Technical Details · 2026-06-30: 104-1604-1804-1904-2004-2904-3006-30
Signal classification3 categories
Disclosure
660.0%
General
330.0%
PoC
110.0%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-04-163
Disclosure2General1
2026-04-182
Disclosure1General1
2026-04-191
Disclosure1
2026-04-201
Disclosure1
2026-04-291
General1
2026-04-301
PoC1
2026-06-301
Disclosure1
Full discourse10 posts
  • Mr. OS@ksg93rd
    PoC

    #exploit #AppSec 1⃣. CVE-2026-42167: RCE, authentication bypass, and privilege escalation in ProFTPD <=1.3.9 https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc 2⃣. CVE-2026-41940: Critical vulnerability in cPanel & WHM allowing session hijacking and authentication bypass via CRLF injection https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ 3⃣. CVE-2026-40478: Thymeleaf server-side template injection vulnerability https://snyk.io/blog/thymeleaf-injection/ 4⃣. CVE-2026-3854: RCE in GitHub*com/GitHub Enterprise Server https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 5⃣. CVE-2026-20079: Critical Cisco FMC Zero-Day https://github.com/0xBlackash/CVE-2026-20079

    Post summary

    The post catalogs several 2026 CVEs, providing direct links to working PoC code and detailed technical information, but does not mention active exploitation or patches.

    01032886
    3.3K followersView on X
  • Brian Vermeer@BrianVerm
    General

    A high CVSS score does not always mean "all hands on deck." It is wiser to assess the situation first before rushing into stress mode. For example, examine CVE-2026-40478 in Thymeleaf. https://snyk.io/blog/thymeleaf-injection/

    Post summary

    The post references CVE-2026-40478 in Thymeleaf but provides no technical, exploit, or mitigation details.

    10040388
    6.8K followersView on X
  • beroal CS@beroal_cs
    Disclosure

    It's About Thyme: How a Whitespace Character Broke Thymeleaf's Expression Sandbox (CVE-2026-40478) | Blog | Endor Labs: https://www.endorlabs.com/learn/its-about-thyme-how-a-whitespace-character-broke-thymeleafs-expression-sandbox-cve-2026-40478

    Post summary

    The article announces a new CVE (CVE-2026-40478) and explains how a whitespace character exploited Thymeleaf's sandbox, providing technical disclosure without mentioning PoC, exploit, or patch details.

    0000047
    55 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40478: Improper neutralization of speci... Thymeleaf's expression sanitization crumbles under specific syntax patterns - classic SSTI goldmine for any Spring app ... https://zerodaysignal.com/vulnerability/CVE-2026-40478 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑40478 is a server‑side template injection flaw in Thymeleaf’s expression sanitization, with technical details and a zero‑day signal link provided for further information.

    0000084
    218 followersView on X
  • Pacific Technology Group@PTGLondon
    Disclosure

    CVE-2026-40478: A whitespace character bypass in Thymeleaf template engine scores CVSS 9.1. Single malicious request = complete server takeover. Most Java web apps aff https://pacific.london/insights/critical-java-template-flaw-exposes-spring-applications-instant-server-takeover

    Post summary

    The message announces a high‑severity CVE in Thymeleaf, explaining a whitespace bypass that permits full server takeover with a single request, without providing a PoC, exploit code, or patch.

    0000050
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40478 Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the t… https://www.cve.org/CVERecord?id=CVE-2026-40478

    Post summary

    The snippet announces CVE-2026-40478 affecting Thymeleaf versions 3.1.3.RELEASE and earlier, describing a security bypass vulnerability but offering no deeper technical or remediation details.

    00000156
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40478 Server-Side Template Injection Security Bypass in Thymeleaf 3.1.3.RELEASE and Prior https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40478

    Post summary

    The message announces CVE-2026-40478, a server‑side template injection security bypass in Thymeleaf 3.1.3.RELEASE and prior, but offers only basic details and no information on PoC, exploitation, or remediation.

    0000076
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical expression neutralization flaw, CVE-2026-40478, affects `Thymeleaf`. This could allow unauthorized expressions, risking code execution or data exposure. #Thymeleaf #infosec #Vulnerability https://www.pulsepatch.io/posts/cve-2026-40478-thymeleaf-expression-neutralization

    Post summary

    The post announces CVE‑2026‑40478 against Thymeleaf, describing an expression neutralization flaw that could enable code execution or data exposure, but it does not detail PoC, exploit, or mitigation.

    0000093
    12 followersView on X
  • DailyCVE@dailycve
    General

    🔴 Thymeleaf, Security Bypass leads to SSTI, #CVE-2026-40478 (Critical) https://dailycve.com/thymeleaf-security-bypass-leads-to-ssti-cve-2026-40478-critical/

    Post summary

    The post announces CVE‑2026‑40478 as a critical Thymeleaf issue involving a security bypass that results in server‑side template injection, but offers no further technical detail, PoC, exploit, patch, or evidence of active attacks.

    0000068
    181 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Thymeleaf, SSTI, #CVE-2026-40478 (High) https://dailycve.com/thymeleaf-ssti-cve-2026-40478-high/

    Post summary

    The tweet announces a high‑severity Thymeleaf Server‑Side Template Injection vulnerability, CVE‑2026‑40478, and links to a DailyCVE article.

    0000064
    181 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appthymeleafthymeleaf---

Explore more