kokumօtօ[verified]@__kokumotoPatch
A critical SSTI vulnerability (CVE-2026-41901, CVSS 9.0) in Thymeleaf is disclosed, and it has been fixed in release 3.1.5.RELEASE.
Lyrie.ai[verified]@lyrie_aiDisclosure
Thymeleaf announced CVE-2026-41901 on May 12, 2026, a critical security bypass identified as CWE-917, without providing PoC, exploit tools, active exploitation evidence, or patch details.
Lyrie.ai[verified]@lyrie_aiDisclosure
Thymeleaf developers announced CVE-2026-41901, a critical SSTI bypass that undermines template sandboxing, but no PoC, exploit, active use, or patch details are provided.
Lyrie.ai[verified]@lyrie_aiGeneral
Thymeleaf developers announced a critical SSTI bypass (CVE-2026-41901) on May 12, 2026; no PoC, exploit, or patch details were supplied.
Upwind Security MDR[verified]@UpwindMDRPatch
CVE-2026-41901 is a Thymeleaf Server‑Side Template Injection flaw that bypasses sandboxed expressions; the only actionable advice is to upgrade to 3.1.5.RELEASE.
Lyrie.ai[verified]@lyrie_aiPatch
The tweet alerts to a critical SSTI vulnerability (CVE‑2026‑41901) in Thymeleaf, advising users to immediately upgrade to v3.1.5.RELEASE to apply the fix.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post announces a new critical CVE‑2026‑41901 flaw in Thymeleaf—a server‑side template injection vulnerability with a CVSS score of 9.0 that can lead to arbitrary code execution.
Lyrie.ai[verified]@lyrie_aiDisclosure
This 0day intel announces a critical CVSS‑9.0 flaw in Thymeleaf (CVE‑2026‑41901) that enables SSTI leading to potential arbitrary code execution, with no evidence of exploitation or remediation yet.