CVE-2026-41901

Remote Code Execution
Affects
Thymeleaf
in
Thymeleaf
No items found.
Versions
<=3.1.4.RELEASE

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Thymeleaf is a modern server-side Java template engine for both web and standalone environments. It processes HTML, XML, text, JavaScript and CSS templates and is widely used as the view layer of Spring MVC and Spring Boot applications. Thymeleaf 3.0.x is the legacy line; Thymeleaf 3.1.x is the current upstream line.

A remote code execution vulnerability (CVE-2026-41901) has been identified in Thymeleaf's restricted (sandboxed) expression mode, which allows attackers whose unsanitized data reaches a restricted context in a template to have expressions executed that the sandbox should block, achieving Server-Side Template Injection (SSTI).

Per OWASP: Code Injection is the general term for attack types which consist of injecting code that is then interpreted/executed by the application. This type of attack exploits poor handling of untrusted data.

This issue affects all versions of Thymeleaf up to and including 3.1.4.RELEASE.

Details

Module Info

Vulnerability Info

This Critical-severity vulnerability is found in the org.thymeleaf:thymeleaf package in all versions of Thymeleaf up to and including 3.1.4.RELEASE.

In restricted contexts, such as expression preprocessing (__${...}__), unescaped text, and fragment and link expressions, Thymeleaf rejects expressions that instantiate objects with new or read request parameters through param before it evaluates them. The check matches those keywords case-sensitively. StandardExpressionUtils compares the expression against lower-case keyword arrays, and treats upper-case letters as identifier characters when it decides where a keyword starts and ends:

private static final char[] NEW_ARRAY = "wen".toCharArray(); // Inverted "new"
private static final int NEW_LEN = NEW_ARRAY.length;
private static final char[] PARAM_ARRAY = "marap".toCharArray(); // Inverted "param"
private static final int PARAM_LEN = PARAM_ARRAY.length;

private static boolean isSafeIdentifierChar(final char c) {
    return (c >= 'A' && c <= 'Z') || (c >= 'a' && c <= 'z') || (c >= '0' && c <= '9') || c == '_';
}

Mixed-case forms such as NEW, NeW, PARAM or pArAm are therefore not recognized and pass the restricted-mode check. In applications that evaluate expressions with Spring's SpEL through the Thymeleaf Spring integrations, the same case-sensitive matching guards restricted expressions, and SpEL accepts the new constructor keyword in any letter case. A mixed-case NEW expression that passes the check is therefore still evaluated as the object instantiation that the sandbox exists to forbid.

Mitigation

Thymeleaf 3.0.x is End-of-Life and will not receive any updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade applications to Thymeleaf 3.1.x.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

Credits

Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Critical
ID
CVE-2026-41901
PROJECT Affected
Thymeleaf
Versions Affected
<=3.1.4.RELEASE
NES Versions Affected
Published date
October 8, 2026
≈ Fix date
October 7, 2026
Category
Remote Code Execution
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Thymeleaf
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.