OVERVIEW CVE-2026-40478 is a Server-Side Template Injection (SSTI) vulnerability affecting Thymeleaf, a widely-used server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass in the expression execution mechanism that fails to properly neutralize specific syntax patterns, allowing attackers to execute unauthorized expressions when applications pass unvalidated user input directly to the template engine. The vulnerability has been remediated in version 3.1.4.RELEASE. SEVERITY This vulnerability carries a CRITICAL CVSS v3.1 score of 9.0 with a network-based attack vector, high attack complexity, requiring no privileges or user interaction. The issue has broad impact, potentially compromising confidentiality, integrity, and availability across the system boundary. An unauthenticated remote attacker can exploit this flaw to achieve arbitrary code execution through template injection, presenting significant risk to affected organizations. EXPLOITATION STATUS The vulnerability is listed on the CISA Known Exploited Vulnerabilities (KEV) Catalog as actively exploited, indicating real-world attacks are occurring. While the EPSS score of 0.0005 is relatively low, the designation as "Active" on the Hot List and its presence in the KEV catalog demonstrate active threat activity. Organizations should prioritize patching to version 3.1.4.RELEASE immediately and review applications for instances of unvalidated user input being passed to Thymeleaf templates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.4CPE matchmatch criteria | cpe:2.3:a:thymeleaf:thymeleaf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.