CVE-2026-41901Disclosure

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constructs that allow this kind of expressions to be executed. If an application developer passes to the template engine unsanitized variables that contain such expressions, and these values are used in sandboxed contexts inside the templates, these expressions can be executed achieving Server-Side Template Injection (SSTI). This vulnerability is fixed in 3.1.5.RELEASE.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-917CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: rising

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 12 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-05-09); latest day: 3
  • 12 total mentions across 7 days

Deep dive

Activity timeline12 mentions / 7d
01234Mentions · 2026-05-04: 1Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-08: 1Mentions · 2026-05-09: 4Mentions · 2026-05-12: 1Mentions · 2026-06-24: 3PoC Mentioned / Linked · 2026-05-06: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-09: 2Technical Details · 2026-05-04: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 4Technical Details · 2026-05-12: 1Technical Details · 2026-06-24: 305-0405-0605-0705-0805-0905-1206-24
Signal classification3 categories
Disclosure
650.0%
Patch
541.7%
General
18.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-041
Patch1
2026-05-061
Patch1
2026-05-071
Patch1
2026-05-081
Disclosure1
2026-05-094
Disclosure2Patch2
2026-05-121
Disclosure1
2026-06-243
Disclosure2General1
Full discourse12 posts
  • Gray Hats@the_yellow_fall
    Patch

    Critical 9.0 CVSS flaw in Thymeleaf (CVE-2026-41901) allows SSTI and arbitrary code execution. Secure your Java web apps—upgrade to v3.1.5.RELEASE now! #Thymeleaf #JavaSecurity #SSTI #CyberSecurity #InfoSec #WebDev #CVE202641901 #JavaDev #PatchAlert https://securityonline.info/thymeleaf-sandbox-bypass-ssti-cve-2026-41901-patch-3-1-5/ https://t.co/cRyXBHr5HM

    Post summary

    The post announces a critical SSTI flaw (CVE‑2026‑41901) in Thymeleaf, urges users to upgrade to v3.1.5.RELEASE, and links to a patch notice.

    0401131.0K
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Thymeleafに重大(Critical)な脆弱性。CVE-2026-41901はCVSSスコア9.0の構文認識不備。未検証の変数が直接テンプレートエンジンに入れられた場合にSSTIが成立する可能性。3.1.5.RELEASEで修正。 https://securityonline.info/thymeleaf-sandbox-bypass-ssti-cve-2026-41901-patch-3-1-5/

    Post summary

    A critical SSTI vulnerability (CVE-2026-41901, CVSS 9.0) in Thymeleaf is disclosed, and it has been fixed in release 3.1.5.RELEASE.

    00063984
    7.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 12, 2026, Thymeleaf developers disclosed CVE-2026-41901, a critical security bypass in the popular Java server-side template engine. The vulnerability is tracked under CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement.

    Post summary

    Thymeleaf announced CVE-2026-41901 on May 12, 2026, a critical security bypass identified as CWE-917, without providing PoC, exploit tools, active exploitation evidence, or patch details.

    1001034
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    12, 2026, — CVE-2026-41901: Thymeleaf SSTI Bypass Breaks Template Sandboxing—Enterprise Java Under Fire. On May 12, 2026, Thymeleaf developers disclosed CVE-2026-41901, a critical security bypass in the popular Java server-side template engine.

    Post summary

    Thymeleaf developers announced CVE-2026-41901, a critical SSTI bypass that undermines template sandboxing, but no PoC, exploit, active use, or patch details are provided.

    1000032
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-41901: Thymeleaf SSTI Bypass Breaks Template Sandboxing—Enterprise Java Under Fire On May 12, 2026, Thymeleaf developers disclosed CVE-2026-41901, a critical security bypass in the popular Java server-side template engine.

    Post summary

    Thymeleaf developers announced a critical SSTI bypass (CVE-2026-41901) on May 12, 2026; no PoC, exploit, or patch details were supplied.

    1000030
    295 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Thymeleaf SSTI (CVE-2026-41901) org.thymeleaf:thymeleaf sandboxed expressions can be bypassed, allowing unsafe template expressions to execute in restricted contexts. 👉 Affects <= 3.1.4.RELEASE 👉 Update to 3.1.5.RELEASE immediately

    Post summary

    CVE-2026-41901 is a Thymeleaf Server‑Side Template Injection flaw that bypasses sandboxed expressions; the only actionable advice is to upgrade to 3.1.5.RELEASE.

    0001093
    122 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41901 Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression … https://www.cve.org/CVERecord?id=CVE-2026-41901

    Post summary

    CVE‑2026‑41901 details a security bypass in Thymeleaf template expressions before version 3.1.5.RELEASE, with no mention of exploitation or mitigation.

    0000082
    57.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Full Tweet Critical 9.0 CVSS flaw in Thymeleaf (CVE-2026-41901) allows SSTI and arbitrary code execution. Secure your Java web apps—upgrade to v3.1.5.RELEASE now!

    Post summary

    The tweet alerts to a critical SSTI vulnerability (CVE‑2026‑41901) in Thymeleaf, advising users to immediately upgrade to v3.1.5.RELEASE to apply the fix.

    0000037
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for CVE-2026 critical Posted: 2026-05-06T13:04:00.000Z Likes: 10 0day Intel: Critical 9.0 CVSS flaw in Thymeleaf (CVE-2026-41901) allows SSTI and arbitrary c

    Post summary

    The post announces a new critical CVE‑2026‑41901 flaw in Thymeleaf—a server‑side template injection vulnerability with a CVSS score of 9.0 that can lead to arbitrary code execution.

    0000045
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: Critical 9.0 CVSS flaw in Thymeleaf (CVE-2026-41901) allows SSTI and arbitrary c

    Post summary

    This 0day intel announces a critical CVSS‑9.0 flaw in Thymeleaf (CVE‑2026‑41901) that enables SSTI leading to potential arbitrary code execution, with no evidence of exploitation or remediation yet.

    0000040
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-41901: Critical 9.0 CVSS flaw in Thymeleaf (CVE-2026-41901) allows SSTI and arbitrary code execution. Secure your Java web apps—upgrade to v3.1.5.RELEASE now! #Thymeleaf #JavaSecurity #SSTI #CyberSecurity #InfoSec #WebDev #CVE202641901 #JavaDev #PatchAlert…

    Post summary

    The snippet highlights the critical Thymeleaf CVE-2026-41901, describing it as a 9.0 CVSS vulnerability that permits SSTI and arbitrary code execution, and urges users to patch by upgrading to version v3.1.5.RELEASE.

    0000039
    197 followersView on X
  • 洛寒兮@LuochancyOWO
    Disclosure

    CVSS 9.0 — Thymeleaf (CVE-2026-41901) · 5月6日 模板沙箱逃逸(SSTI),远程服务端模板注入。用了 Thymeleaf 3.1.5 以前版本的 Java 项目全受影响。 5.7-5.8大量高危漏洞披露 Linux、K8S、Java全线贯穿

    Post summary

    The content announces CVE-2026-41901 with a CVSS 9.0 score, detailing a server‑side template injection via Thymeleaf's sandbox escape affecting all Java projects using versions prior to 3.1.5.

    00000127
    809 followersView on X

Explore more