CVE-2026-41901
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Thymeleaf is a modern server-side Java template engine for both web and standalone environments. It processes HTML, XML, text, JavaScript and CSS templates and is widely used as the view layer of Spring MVC and Spring Boot applications. Thymeleaf 3.0.x is the legacy line; Thymeleaf 3.1.x is the current upstream line.
A remote code execution vulnerability (CVE-2026-41901) has been identified in Thymeleaf's restricted (sandboxed) expression mode, which allows attackers whose unsanitized data reaches a restricted context in a template to have expressions executed that the sandbox should block, achieving Server-Side Template Injection (SSTI).
Per OWASP: Code Injection is the general term for attack types which consist of injecting code that is then interpreted/executed by the application. This type of attack exploits poor handling of untrusted data.
This issue affects all versions of Thymeleaf up to and including 3.1.4.RELEASE.
Details
Module Info
- Product: Thymeleaf
- Affected packages:
org.thymeleaf:thymeleaf,org.thymeleaf:thymeleaf-spring5,org.thymeleaf:thymeleaf-spring6 - Affected versions: <=3.1.4.RELEASE
- GitHub repository: https://github.com/thymeleaf/thymeleaf
- Published packages: https://central.sonatype.com/artifact/org.thymeleaf/thymeleaf
- Package manager: Maven
- Fixed in:
- OSS Thymeleaf 3.1.5.RELEASE
- NES for Thymeleaf v3.0.17
Vulnerability Info
This Critical-severity vulnerability is found in the org.thymeleaf:thymeleaf package in all versions of Thymeleaf up to and including 3.1.4.RELEASE.
In restricted contexts, such as expression preprocessing (__${...}__), unescaped text, and fragment and link expressions, Thymeleaf rejects expressions that instantiate objects with new or read request parameters through param before it evaluates them. The check matches those keywords case-sensitively. StandardExpressionUtils compares the expression against lower-case keyword arrays, and treats upper-case letters as identifier characters when it decides where a keyword starts and ends:
private static final char[] NEW_ARRAY = "wen".toCharArray(); // Inverted "new"
private static final int NEW_LEN = NEW_ARRAY.length;
private static final char[] PARAM_ARRAY = "marap".toCharArray(); // Inverted "param"
private static final int PARAM_LEN = PARAM_ARRAY.length;
private static boolean isSafeIdentifierChar(final char c) {
return (c >= 'A' && c <= 'Z') || (c >= 'a' && c <= 'z') || (c >= '0' && c <= '9') || c == '_';
}Mixed-case forms such as NEW, NeW, PARAM or pArAm are therefore not recognized and pass the restricted-mode check. In applications that evaluate expressions with Spring's SpEL through the Thymeleaf Spring integrations, the same case-sensitive matching guards restricted expressions, and SpEL accepts the new constructor keyword in any letter case. A mixed-case NEW expression that passes the check is therefore still evaluated as the object instantiation that the sandbox exists to forbid.
Mitigation
Thymeleaf 3.0.x is End-of-Life and will not receive any updates to address this issue.
Users of the affected components should apply one of the following mitigations:
- Upgrade applications to Thymeleaf 3.1.x.
- Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- Cristian-Alexandru Staicu from Endor Labs (finder)