CVE-2026-40478

Remote Code Execution
Affects
Thymeleaf
in
Thymeleaf
No items found.
Versions
<=3.1.3.RELEASE

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Thymeleaf is a modern server-side Java template engine for both web and standalone environments. It processes HTML, XML, text, JavaScript and CSS templates and is widely used as the view layer of Spring MVC and Spring Boot applications. Thymeleaf 3.0.x is the legacy line; Thymeleaf 3.1.x is the current upstream line.

A remote code execution vulnerability (CVE-2026-40478) has been identified in Thymeleaf's expression execution, which allows attackers who can get unvalidated input into a template expression to use specific syntax patterns that the engine fails to neutralize, executing unauthorized expressions and achieving Server-Side Template Injection (SSTI).

Per OWASP: Code Injection is the general term for attack types which consist of injecting code that is then interpreted/executed by the application. This type of attack exploits poor handling of untrusted data.

This issue affects all versions of Thymeleaf up to and including 3.1.3.RELEASE.

Details

Module Info

Vulnerability Info

This Critical-severity vulnerability is found in the org.thymeleaf:thymeleaf package in all versions of Thymeleaf up to and including 3.1.3.RELEASE.

Thymeleaf evaluates expressions that may carry untrusted input in a restricted execution mode, which is meant to stop an injected expression from instantiating objects, reaching static members or reading request parameters. Two parts of that protection work on the expression exactly as it is written.

First, the restricted-mode check in StandardExpressionUtils.containsOGNLInstantiationOrStaticOrParam() scans the raw expression text for the new keyword, the @...@ static-access syntax and the param variable. It does not normalize the expression first, so whitespace and control characters embedded in those tokens reach the scan unchanged and change what it sees:

public static boolean containsOGNLInstantiationOrStaticOrParam(final String expression) {

    final int explen = expression.length();
    int n = explen;
    int ni = 0; // index for computing position in the NEW_ARRAY
    int pi = 0; // index for computing position in the PARAM_ARRAY
    int si = -1;
    char c;
    while (n-- != 0) {

        c = expression.charAt(n);
        // ...

Second, type references in expressions (new SomeClass(), @SomeClass@member) are checked only against a short blacklist of java.* classes. Classes from every other package can be referenced, including bytecode and reflection libraries such as Javassist, Byte Buddy, cglib and ASM, and Jackson and Spring framework classes:

public static boolean isTypeAllowed(final String typeName) {
    Validate.notNull(typeName, "Type name cannot be null");
    final int i0 = typeName.indexOf('.');
    if (i0 >= 0) {
        final String package0 = typeName.substring(0, i0);
        if ("java".equals(package0)) { // This is the only prefix that might be blacklisted
            for (final String prefix : BLACKLISTED_CLASS_NAME_PREFIXES) {
                if (typeName.startsWith(prefix)) {
                    return false;
                }
            }
        }
    }
    // This is safe assuming we have disabled the capability of calling "java.lang" classes without package
    return true;
}

An expression such as @javassist.ClassPool@getDefault() therefore evaluates and returns a live bytecode-generation object whenever Javassist is on the application's classpath.

Mitigation

Thymeleaf 3.0.x is End-of-Life and will not receive any updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade applications to Thymeleaf 3.1.x.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

Credits

  • Dawid Bakaj from VIPentest.com (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Critical
ID
CVE-2026-40478
PROJECT Affected
Thymeleaf
Versions Affected
<=3.1.3.RELEASE
NES Versions Affected
Published date
October 8, 2026
≈ Fix date
October 7, 2026
Category
Remote Code Execution
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Thymeleaf
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.