THREAT OPS › Threat News › [NVD] CVE-2026-40478 (CRITICAL 9.0) — Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it f
[NVD] CVE-2026-40478 (CRITICAL 9.0) — Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it f
CVE-2026-40478 CVSS: 9.0 CRITICAL Published: 2026-04-17T22:16:33.650
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patter
MITRE ATT&CK techniques
- Template InjectionT1221
Indicators of compromise
- CVE-2026-40478cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40478