Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40477

33
FAUCET Score

OVERVIEW CVE-2026-40477 is a critical security bypass vulnerability in Thymeleaf, a widely-used server-side Java template engine, affecting versions 3.1.3.RELEASE and earlier. The flaw exists in the expression execution mechanisms, where improper scope restrictions on accessible objects allow attackers to circumvent the library's expression injection protections and achieve Server-Side Template Injection (SSTI). The vulnerability requires applications to pass unvalidated user input directly to the template engine to be exploitable. This issue has been resolved in version 3.1.4.RELEASE. SEVERITY The vulnerability carries a CVSS 3.1 severity rating of 9.0 CRITICAL with a network-based attack vector that requires high complexity but no privileges or user interaction. An unauthenticated remote attacker exploiting this flaw could achieve complete compromise of confidentiality, integrity, and availability across the system boundary. The FAUCET Risk Score of 52.0/100 indicates significant operational concern, though the EPSS score of 0.000510000 suggests relatively low current exploitation probability compared to other disclosed vulnerabilities. EXPLOITATION STATUS While the vulnerability is currently listed as ACTIVE on the Hot List, it is not yet documented in the CISA Known Exploited Vulnerabilities catalog, indicating no confirmed active exploitation in the wild at this time. However, organizations running vulnerable Thymeleaf versions should prioritize immediate patching given the critical severity rating and the straightforward nature of SSTI attacks once template injection is achieved. Community attention to this vulnerability is expected to increase as awareness spreads, making prompt remediation essential.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.1.4CPE matchmatch criteria
cpe:2.3:a:thymeleaf:thymeleaf:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.0CRITICAL

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.86%
Probability of exploitation in next 30 days
EPSS Percentile
54.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0086 is in the 51st percentile among its peer group of 200 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.1 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

access.redhat.com / errata/RHSA-2026:21772
access.redhat.com / security/cve/CVE-2026-40477
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-40477.json
github.com / thymeleaf/thymeleaf/security/advisories/GHSA-r4v4-5mwr-2fwr
Vendor Advisory