Tag
critical
advisory
Thymeleaf Server-Side Template Injection Vulnerability
2 rules 1 TTPThymeleaf versions up to 3.1.3.RELEASE are vulnerable to server-side template injection (SSTI) due to improper neutralization of specific syntax patterns, allowing attackers to execute unauthorized expressions when unvalidated user input is passed directly to the template engine.
Thymeleaf +2
ssti
cve-2026-40478
server-side template injection
expression injection
2r
1t
critical
advisory
Thymeleaf Server-Side Template Injection Vulnerability
2 rules 1 TTPA server-side template injection vulnerability exists in Thymeleaf versions up to 3.1.4.RELEASE due to improper neutralization of specific constructs, allowing the execution of potentially dangerous expressions in sandboxed contexts if unsanitized variables are passed to the template engine.
thymeleaf +2
ssti
template-injection
cve-2026-41901
2r
1t