CVE-2026-40477Critical· 9.0▾ AbyssalPoC availableThymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanism…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 49.5 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
1 GitHub repo
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached from within a template. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.
thymeleaf < 3.1.4Upgrade past the affected range:
thymeleaf 3.1.4Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40478Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments
CVE-2026-91925High· 8.8Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code
CVE-2026-91145High· 7.1Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering
CVE-2026-75650Critical· 10.0Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2024-23692Critical· 9.8Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability
CVE-2026-65591Highn8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution