CVE-2026-40478
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Thymeleaf is a modern server-side Java template engine for both web and standalone environments. It processes HTML, XML, text, JavaScript and CSS templates and is widely used as the view layer of Spring MVC and Spring Boot applications. Thymeleaf 3.0.x is the legacy line; Thymeleaf 3.1.x is the current upstream line.
A remote code execution vulnerability (CVE-2026-40478) has been identified in Thymeleaf's expression execution, which allows attackers who can get unvalidated input into a template expression to use specific syntax patterns that the engine fails to neutralize, executing unauthorized expressions and achieving Server-Side Template Injection (SSTI).
Per OWASP: Code Injection is the general term for attack types which consist of injecting code that is then interpreted/executed by the application. This type of attack exploits poor handling of untrusted data.
This issue affects all versions of Thymeleaf up to and including 3.1.3.RELEASE.
Details
Module Info
- Product: Thymeleaf
- Affected packages:
org.thymeleaf:thymeleaf,org.thymeleaf:thymeleaf-spring5,org.thymeleaf:thymeleaf-spring6 - Affected versions: <=3.1.3.RELEASE
- GitHub repository: https://github.com/thymeleaf/thymeleaf
- Published packages: https://central.sonatype.com/artifact/org.thymeleaf/thymeleaf
- Package manager: Maven
- Fixed in:
- OSS Thymeleaf 3.1.4.RELEASE
- NES for Thymeleaf v3.0.17
Vulnerability Info
This Critical-severity vulnerability is found in the org.thymeleaf:thymeleaf package in all versions of Thymeleaf up to and including 3.1.3.RELEASE.
Thymeleaf evaluates expressions that may carry untrusted input in a restricted execution mode, which is meant to stop an injected expression from instantiating objects, reaching static members or reading request parameters. Two parts of that protection work on the expression exactly as it is written.
First, the restricted-mode check in StandardExpressionUtils.containsOGNLInstantiationOrStaticOrParam() scans the raw expression text for the new keyword, the @...@ static-access syntax and the param variable. It does not normalize the expression first, so whitespace and control characters embedded in those tokens reach the scan unchanged and change what it sees:
public static boolean containsOGNLInstantiationOrStaticOrParam(final String expression) {
final int explen = expression.length();
int n = explen;
int ni = 0; // index for computing position in the NEW_ARRAY
int pi = 0; // index for computing position in the PARAM_ARRAY
int si = -1;
char c;
while (n-- != 0) {
c = expression.charAt(n);
// ...Second, type references in expressions (new SomeClass(), @SomeClass@member) are checked only against a short blacklist of java.* classes. Classes from every other package can be referenced, including bytecode and reflection libraries such as Javassist, Byte Buddy, cglib and ASM, and Jackson and Spring framework classes:
public static boolean isTypeAllowed(final String typeName) {
Validate.notNull(typeName, "Type name cannot be null");
final int i0 = typeName.indexOf('.');
if (i0 >= 0) {
final String package0 = typeName.substring(0, i0);
if ("java".equals(package0)) { // This is the only prefix that might be blacklisted
for (final String prefix : BLACKLISTED_CLASS_NAME_PREFIXES) {
if (typeName.startsWith(prefix)) {
return false;
}
}
}
}
// This is safe assuming we have disabled the capability of calling "java.lang" classes without package
return true;
}An expression such as @javassist.ClassPool@getDefault() therefore evaluates and returns a live bytecode-generation object whenever Javassist is on the application's classpath.
Mitigation
Thymeleaf 3.0.x is End-of-Life and will not receive any updates to address this issue.
Users of the affected components should apply one of the following mitigations:
- Upgrade applications to Thymeleaf 3.1.x.
- Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- Dawid Bakaj from VIPentest.com (finder)