CVE-2026-40478

Source
https://cve.org/CVERecord?id=CVE-2026-40478
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40478.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40478
Aliases
Published
2026-04-17T21:57:01.560Z
Modified
2026-07-16T03:31:14.847140273Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
Details

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of unauthorized expressions. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.

Database specific
{
    "cwe_ids": [
        "CWE-1336",
        "CWE-917"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40478.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/thymeleaf/thymeleaf

Affected ranges

Type
GIT
Repo
https://github.com/thymeleaf/thymeleaf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:thymeleaf:thymeleaf:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.1.4.RELEASE"
        },
        {
            "fixed": "3.1.4"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

thymeleaf-2.*
thymeleaf-2.0.0
thymeleaf-2.0.0-beta1
thymeleaf-2.0.0-beta2
thymeleaf-2.0.1
thymeleaf-2.0.10
thymeleaf-2.0.11
thymeleaf-2.0.12
thymeleaf-2.0.13
thymeleaf-2.0.14
thymeleaf-2.0.15
thymeleaf-2.0.16
thymeleaf-2.0.2
thymeleaf-2.0.3
thymeleaf-2.0.4
thymeleaf-2.0.5
thymeleaf-2.0.6
thymeleaf-2.0.7
thymeleaf-2.0.8
thymeleaf-2.0.9
thymeleaf-2.1.0-beta1
thymeleaf-2.1.0-beta2
thymeleaf-2.1.0-m1
thymeleaf-2.1.0-m2
thymeleaf-2.1.0-m3
thymeleaf-2.1.0.RELEASE
thymeleaf-2.1.1.RELEASE
thymeleaf-2.1.2.RELEASE
thymeleaf-2.1.3.RELEASE
thymeleaf-3.*
thymeleaf-3.0.0.ALPHA01
thymeleaf-3.0.0.ALPHA02
thymeleaf-3.0.0.ALPHA03
thymeleaf-3.0.0.BETA01
thymeleaf-3.0.0.BETA02
thymeleaf-3.0.0.BETA03
thymeleaf-3.0.0.RELEASE
thymeleaf-3.0.1.RELEASE
thymeleaf-3.0.10.RELEASE
thymeleaf-3.0.11.RELEASE
thymeleaf-3.0.12.RELEASE
thymeleaf-3.0.13.RELEASE
thymeleaf-3.0.14.RELEASE
thymeleaf-3.0.2.RELEASE
thymeleaf-3.0.3.RELEASE
thymeleaf-3.0.4.RELEASE
thymeleaf-3.0.5.RELEASE
thymeleaf-3.0.6.RELEASE
thymeleaf-3.0.7.RELEASE
thymeleaf-3.0.8.RELEASE
thymeleaf-3.0.9.RELEASE
thymeleaf-3.1.0.M1
thymeleaf-3.1.0.M2
thymeleaf-3.1.0.M2-dev01
thymeleaf-3.1.0.M3
thymeleaf-3.1.0.RC1
thymeleaf-3.1.0.RC2
thymeleaf-3.1.0.RELEASE
thymeleaf-3.1.1.RELEASE
thymeleaf-3.1.2.RELEASE
thymeleaf-3.1.3.RELEASE

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40478.json"