Critical 9.0 CVSS Flaw in Thymeleaf Enables Remote Server Injection
ID: ac0718f1-2643-58d0-978a-efeff05114eb
STIX ID: report--ac0718f1-2643-58d0-978a-efeff05114eb
Feed Name: securityonline.info
Threat Score
Thymeleaf released a critical security fix for CVE-2026-41901 (CVSS 9.0): a sandbox bypass in the expression execution engine that can lead to Server-Side Template Injection (SSTI) and potential arbitrary code execution. The issue arises from improper recognition of unauthorized syntax allowing malicious expressions in unsanitized template variables to escape sandbox restrictions; users are urged to upgrade to 3.1.5.RELEASE immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
