thymeleaf vulnerabilities
CVEs whose affected-version data names the thymeleaf package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-40478Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mecha…
▾ Midnightthymeleaf · thymeleafEPSS 1.1%via NVD
CVE-2026-40477Critical· 9.0PoCThymeleaf is a server-side Java template engine for web and standalone environments
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanism…
▾ Abyssalthymeleaf · thymeleafEPSS 0.85%via NVD