logo

Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine

ID: 7eac2a72-d863-5fa5-bcf1-5e258671cba0

STIX ID: report--7eac2a72-d863-5fa5-bcf1-5e258671cba0

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Ddos

...
...

Thymeleaf released version 3.1.4.RELEASE to fix two high-severity SSTI vulnerabilities (CVE-2026-40477 and CVE-2026-40478, CVSS 9.1) that allow unauthenticated attackers to reach sensitive internal objects or bypass expression neutralization when applications pass unvalidated user input to templates; developers must upgrade and ensure user-controlled data is never used to construct template names or expressions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.