CVE Explorer
CVE-2026-41901
Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constructs that allow this kind of expressions to be executed. If an application developer passes to the te
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-917","description":"CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2494d02ff1670a822f6ddcfd29e908b4979d4d29575bd49a207c2c3f11d7e581 · sha256:bc0b3065a92d1469… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-1336","description":"CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2494d02ff1670a822f6ddcfd29e908b4979d4d29575bd49a207c2c3f11d7e581 · sha256:bc0b3065a92d1469… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"thymeleaf","vendor":"thymeleaf","versions":[{"status":"affected","version":"< 3.1.5.RELEASE"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2494d02ff1670a822f6ddcfd29e908b4979d4d29575bd49a207c2c3f11d7e581 · sha256:bc0b3065a92d1469… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2494d02ff1670a822f6ddcfd29e908b4979d4d29575bd49a207c2c3f11d7e581 · sha256:bc0b3065a92d1469… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-917","description":"CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2494d02ff1670a822f6ddcfd29e908b4979d4d29575bd49a207c2c3f11d7e581 · sha256:bc0b3065a92d1469… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-1336","description":"CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2494d02ff1670a822f6ddcfd29e908b4979d4d29575bd49a207c2c3f11d7e581 · sha256:bc0b3065a92d1469… · /containers/cna/problemTypes/1/descriptions/0
Source references
1 source assertion{"name":"https://github.com/thymeleaf/thymeleaf/security/advisories/GHSA-c9ph-gxww-7744","tags":["x_refsource_CONFIRM"],"url":"https://github.com/thymeleaf/thymeleaf/security/advisories/GHSA-c9ph-gxww-7744"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2494d02ff1670a822f6ddcfd29e908b4979d4d29575bd49a207c2c3f11d7e581 · sha256:bc0b3065a92d1469… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.