Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41901

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 9
EPSS Низкий

Описание

Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constructs that allow this kind of expressions to be executed. If an application developer passes to the template engine unsanitized variables that contain such expressions, and these values are used in sandboxed contexts inside the templates, these expressions can be executed achieving Server-Side Template Injection (SSTI). This vulnerability is fixed in 3.1.5.RELEASE.

A flaw was found in Thymeleaf, a server-side Java template engine. A security bypass vulnerability exists in its expression execution mechanisms, allowing specific constructs to be executed even in restricted sandboxed contexts. If an application developer passes unsanitized variables containing malicious expressions to the template engine, a remote attacker could exploit this to achieve Server-Side Template Injection (SSTI), potentially leading to arbitrary code execution.

Отчет

This is an Important security bypass in Thymeleaf's expression execution, allowing Server-Side Template Injection (SSTI). The flaw enables arbitrary code execution if an application processes unsanitized input containing malicious expressions within sandboxed template contexts. Red Hat OpenShift Dev Spaces is not affected by this vulnerability as each version ships with a patched version of Thymeleaf 3.1.5.RELEASE. Thymeleaf is only used in Red Hat OpenShift Dev Spaces for email generation rather than web request handling which limits the severity of this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7thymeleafWill not fix
Red Hat JBoss Enterprise Application Platform Expansion PackthymeleafNot affected
Red Hat OpenShift Dev Spacesdevspaces/openvsx-rhel9Not affected
Red Hat OpenShift Dev Spacesdevspaces/pluginregistry-rhel9Not affected
Red Hat Single Sign-On 7thymeleafFix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-917
https://bugzilla.redhat.com/show_bug.cgi?id=2476895thymeleaf: Thymeleaf: Server-Side Template Injection (SSTI) via expression execution bypass

EPSS

Процентиль: 35%
0.00427
Низкий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9
nvd
3 месяца назад

Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constructs that allow this kind of expressions to be executed. If an application developer passes to the template engine unsanitized variables that contain such expressions, and these values are used in sandboxed contexts inside the templates, these expressions can be executed achieving Server-Side Template Injection (SSTI). This vulnerability is fixed in 3.1.5.RELEASE.

CVSS3: 9
github
3 месяца назад

Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns

CVSS3: 9
fstec
3 месяца назад

Уязвимость JavaScript-движка Thymeleaf, связанная с непринятием мер по нейтрализации специальных элементов, используемых в операторе языка выражений, позволяющая нарушителю реализовать атаку внедрения шаблонов на стороне сервера (Server Side Template Injection (SSTI))

EPSS

Процентиль: 35%
0.00427
Низкий

9 Critical

CVSS3