CVE-2026-40477

Source
https://cve.org/CVERecord?id=CVE-2026-40477
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40477.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40477
Aliases
Published
2026-04-17T21:53:47.271Z
Modified
2026-07-16T03:30:49.174994703Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Improper restriction of the scope of accessible objects in Thymeleaf expressions
Details

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached from within a template. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.

Database specific
{
    "cwe_ids": [
        "CWE-1336",
        "CWE-917"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40477.json"
}
References

Affected packages

Git / github.com/thymeleaf/thymeleaf

Affected ranges

Type
GIT
Repo
https://github.com/thymeleaf/thymeleaf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "cpe": "cpe:2.3:a:thymeleaf:thymeleaf:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.1.4.RELEASE"
        },
        {
            "fixed": "3.1.4"
        }
    ]
}

Affected versions

thymeleaf-2.*
thymeleaf-2.0.0
thymeleaf-2.0.0-beta1
thymeleaf-2.0.0-beta2
thymeleaf-2.0.1
thymeleaf-2.0.10
thymeleaf-2.0.11
thymeleaf-2.0.12
thymeleaf-2.0.13
thymeleaf-2.0.14
thymeleaf-2.0.15
thymeleaf-2.0.16
thymeleaf-2.0.2
thymeleaf-2.0.3
thymeleaf-2.0.4
thymeleaf-2.0.5
thymeleaf-2.0.6
thymeleaf-2.0.7
thymeleaf-2.0.8
thymeleaf-2.0.9
thymeleaf-2.1.0-beta1
thymeleaf-2.1.0-beta2
thymeleaf-2.1.0-m1
thymeleaf-2.1.0-m2
thymeleaf-2.1.0-m3
thymeleaf-2.1.0.RELEASE
thymeleaf-2.1.1.RELEASE
thymeleaf-2.1.2.RELEASE
thymeleaf-2.1.3.RELEASE
thymeleaf-3.*
thymeleaf-3.0.0.ALPHA01
thymeleaf-3.0.0.ALPHA02
thymeleaf-3.0.0.ALPHA03
thymeleaf-3.0.0.BETA01
thymeleaf-3.0.0.BETA02
thymeleaf-3.0.0.BETA03
thymeleaf-3.0.0.RELEASE
thymeleaf-3.0.1.RELEASE
thymeleaf-3.0.10.RELEASE
thymeleaf-3.0.11.RELEASE
thymeleaf-3.0.12.RELEASE
thymeleaf-3.0.13.RELEASE
thymeleaf-3.0.14.RELEASE
thymeleaf-3.0.2.RELEASE
thymeleaf-3.0.3.RELEASE
thymeleaf-3.0.4.RELEASE
thymeleaf-3.0.5.RELEASE
thymeleaf-3.0.6.RELEASE
thymeleaf-3.0.7.RELEASE
thymeleaf-3.0.8.RELEASE
thymeleaf-3.0.9.RELEASE
thymeleaf-3.1.0.M1
thymeleaf-3.1.0.M2
thymeleaf-3.1.0.M2-dev01
thymeleaf-3.1.0.M3
thymeleaf-3.1.0.RC1
thymeleaf-3.1.0.RC2
thymeleaf-3.1.0.RELEASE
thymeleaf-3.1.1.RELEASE
thymeleaf-3.1.2.RELEASE
thymeleaf-3.1.3.RELEASE

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40477.json"