CVE-2026-41901

Source
https://cve.org/CVERecord?id=CVE-2026-41901
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41901.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-41901
Aliases
Published
2026-05-12T22:35:50.617Z
Modified
2026-07-15T01:49:05.592635161Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Thymeleaf: Improper recognition of unauthorized syntax patterns in sandboxed Thymeleaf expressions
Details

Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constructs that allow this kind of expressions to be executed. If an application developer passes to the template engine unsanitized variables that contain such expressions, and these values are used in sandboxed contexts inside the templates, these expressions can be executed achieving Server-Side Template Injection (SSTI). This vulnerability is fixed in 3.1.5.RELEASE.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41901.json",
    "cwe_ids": [
        "CWE-1336",
        "CWE-917"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/thymeleaf/thymeleaf

Affected ranges

Type
GIT
Repo
https://github.com/thymeleaf/thymeleaf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.1.5.RELEASE"
        }
    ]
}

Affected versions

thymeleaf-2.*
thymeleaf-2.0.0
thymeleaf-2.0.0-beta1
thymeleaf-2.0.0-beta2
thymeleaf-2.0.1
thymeleaf-2.0.10
thymeleaf-2.0.11
thymeleaf-2.0.12
thymeleaf-2.0.13
thymeleaf-2.0.14
thymeleaf-2.0.15
thymeleaf-2.0.16
thymeleaf-2.0.2
thymeleaf-2.0.3
thymeleaf-2.0.4
thymeleaf-2.0.5
thymeleaf-2.0.6
thymeleaf-2.0.7
thymeleaf-2.0.8
thymeleaf-2.0.9
thymeleaf-2.1.0-beta1
thymeleaf-2.1.0-beta2
thymeleaf-2.1.0-m1
thymeleaf-2.1.0-m2
thymeleaf-2.1.0-m3
thymeleaf-2.1.0.RELEASE
thymeleaf-2.1.1.RELEASE
thymeleaf-2.1.2.RELEASE
thymeleaf-2.1.3.RELEASE
thymeleaf-3.*
thymeleaf-3.0.0.ALPHA01
thymeleaf-3.0.0.ALPHA02
thymeleaf-3.0.0.ALPHA03
thymeleaf-3.0.0.BETA01
thymeleaf-3.0.0.BETA02
thymeleaf-3.0.0.BETA03
thymeleaf-3.0.0.RELEASE
thymeleaf-3.0.1.RELEASE
thymeleaf-3.0.10.RELEASE
thymeleaf-3.0.11.RELEASE
thymeleaf-3.0.12.RELEASE
thymeleaf-3.0.13.RELEASE
thymeleaf-3.0.14.RELEASE
thymeleaf-3.0.2.RELEASE
thymeleaf-3.0.3.RELEASE
thymeleaf-3.0.4.RELEASE
thymeleaf-3.0.5.RELEASE
thymeleaf-3.0.6.RELEASE
thymeleaf-3.0.7.RELEASE
thymeleaf-3.0.8.RELEASE
thymeleaf-3.0.9.RELEASE
thymeleaf-3.1.0.M1
thymeleaf-3.1.0.M2
thymeleaf-3.1.0.M2-dev01
thymeleaf-3.1.0.M3
thymeleaf-3.1.0.RC1
thymeleaf-3.1.0.RC2
thymeleaf-3.1.0.RELEASE
thymeleaf-3.1.1.RELEASE
thymeleaf-3.1.2.RELEASE
thymeleaf-3.1.3.RELEASE
thymeleaf-3.1.4.RELEASE

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41901.json"