boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-40477CRITICAL
thymeleaf thymeleaf — Improper restriction of the scope of accessible objects in Thymeleaf expressions
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  H    9.0   .0085   55.3     —
AFFECTED
  Product                          Versions           Fixed
  thymeleaf                        < 3.1.4.RELEASE –  —
  org.thymeleaf:thymeleaf-spring5  < 3.1.4.RELEASE –  —
  org.thymeleaf:thymeleaf-spring6  < 3.1.4.RELEASE –  —
TIMELINE
  Apr 13  Reserved by GitHub_M
  Apr 17  Published (CNA: GitHub_M)
  Aug 4   RESCORED — CVE-2026-40477 (thymeleaf). CVSS 9.1 → 9 (NVD).
CWE-917, CWE-1336 · CNA: GitHub_M · CVSS v3.1 · 5 references · NVD status: Modified

Description

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached from within a template. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
April 13, 2026ReservedReserved by GitHub_M
April 17, 2026PublishedPublished (CNA: GitHub_M)
August 4, 2026RESCOREDRESCORED — CVE-2026-40477 (thymeleaf). CVSS 9.1 → 9 (NVD).

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
thymeleafthymeleaf< 3.1.4.RELEASE
thymeleaforg.thymeleaf:thymeleaf-spring5< 3.1.4.RELEASE
thymeleaforg.thymeleaf:thymeleaf-spring6< 3.1.4.RELEASE

Weaknesses

CWE-917 · CWE-1336

References (5)

Related

Authoritative record: CVE-2026-40477 at cve.org

Vendors: thymeleaf

Weaknesses: CWE-917 · CWE-1336

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-40477 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.