logo

Critical 9.0 CVSS Flaw in Thymeleaf Enables Remote Server Injection

ID: ac0718f1-2643-58d0-978a-efeff05114eb

STIX ID: report--ac0718f1-2643-58d0-978a-efeff05114eb

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Ddos

...
...

Thymeleaf released a critical security fix for CVE-2026-41901 (CVSS 9.0): a sandbox bypass in the expression execution engine that can lead to Server-Side Template Injection (SSTI) and potential arbitrary code execution. The issue arises from improper recognition of unauthorized syntax allowing malicious expressions in unsanitized template variables to escape sandbox restrictions; users are urged to upgrade to 3.1.5.RELEASE immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.