Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
ID: 7eac2a72-d863-5fa5-bcf1-5e258671cba0
STIX ID: report--7eac2a72-d863-5fa5-bcf1-5e258671cba0
Feed Name: securityonline.info
Threat Score
Thymeleaf released version 3.1.4.RELEASE to fix two high-severity SSTI vulnerabilities (CVE-2026-40477 and CVE-2026-40478, CVSS 9.1) that allow unauthenticated attackers to reach sensitive internal objects or bypass expression neutralization when applications pass unvalidated user input to templates; developers must upgrade and ensure user-controlled data is never used to construct template names or expressions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
