OVERVIEW CVE-2026-40477 is a critical security bypass vulnerability in Thymeleaf, a widely-used server-side Java template engine, affecting versions 3.1.3.RELEASE and earlier. The flaw exists in the expression execution mechanisms, where improper scope restrictions on accessible objects allow attackers to circumvent the library's expression injection protections and achieve Server-Side Template Injection (SSTI). The vulnerability requires applications to pass unvalidated user input directly to the template engine to be exploitable. This issue has been resolved in version 3.1.4.RELEASE. SEVERITY The vulnerability carries a CVSS 3.1 severity rating of 9.0 CRITICAL with a network-based attack vector that requires high complexity but no privileges or user interaction. An unauthenticated remote attacker exploiting this flaw could achieve complete compromise of confidentiality, integrity, and availability across the system boundary. The FAUCET Risk Score of 52.0/100 indicates significant operational concern, though the EPSS score of 0.000510000 suggests relatively low current exploitation probability compared to other disclosed vulnerabilities. EXPLOITATION STATUS While the vulnerability is currently listed as ACTIVE on the Hot List, it is not yet documented in the CISA Known Exploited Vulnerabilities catalog, indicating no confirmed active exploitation in the wild at this time. However, organizations running vulnerable Thymeleaf versions should prioritize immediate patching given the critical severity rating and the straightforward nature of SSTI attacks once template injection is achieved. Community attention to this vulnerability is expected to increase as awareness spreads, making prompt remediation essential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.4CPE matchmatch criteria | cpe:2.3:a:thymeleaf:thymeleaf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.1 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.