CVE-2026-40478Critical· 9.0▾ MidnightThymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mecha…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 49.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
0.8% → 1.1%
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of unauthorized expressions. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.
thymeleaf < 3.1.4Upgrade past the affected range:
thymeleaf 3.1.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40477Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments
CVE-2026-94109High· 8.8openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration
CVE-2026-61453MediumGrav: XSS Blueprint Validation Bypass via Twig String Concatenation
CVE-2026-92592High· 8.8Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bou…
CVE-2026-88064High· 8.8Backstage is an open framework for building developer portals
CVE-2026-91925High· 8.8Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code