Server-Side Template Injection in Thymeleaf by Thymeleaf
⚠️ CVE-Referenzen:
CVE-2026-41901
Thymeleaf - Thymeleaf - CRITICAL - CVE-2026-41901.
Thymeleaf is a widely used Java template engine that is vulnerable to a security bypass issue in its expression execution mechanisms prior to version 3.1.5.RELEASE. This vulnerability occurs when unsanitized variables containing potentially harmful expressions are passed into the template engine. If these variables are utilized within sandboxed contexts in the templates, there is a risk of Server-Side Template Injection (SSTI), allowing remote attackers to execute arbitrary code. Developers are encouraged to upgrade to the latest version to mitigate this risk.
Quelle: securityvulnerability.io