Thymeleaf is a Java template engine embedded across web applications and server-side rendering frameworks, where its disclosures cluster consistently around template and expression-language injection vulnerabilities. The recurring weakness classes—template-engine neutralization failures, expression-language injection, code injection, and command injection—reflect the inherent risks of dynamic expression evaluation in templating contexts and underscore the importance of strict input validation at template boundaries.
The number and severity of CVEs published that impact products developed by Thymeleaf over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40478CRITICAL Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression | Apr 17, 2026 | 9.0 | 35 | NO | NO |
CVE-2026-40477CRITICAL Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression exec | Apr 17, 2026 | 9.0 | 33 | NO | NO |
CVE-2021-43466CRITICAL In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution. | Nov 9, 2021 | 9.8 | 32 | NO | NO |
CVE-2023-38286HIGH Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant | Jul 14, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thymeleaf.
Media articles that mention a CVE ID that affects a product developed by Thymeleaf — matched by CVE ID, not by vendor name.