CVE-2026-40478
Attacker can take control of web servers using Thymeleaf by sending specially crafted input.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical flaw in the Thymeleaf Java template engine allows attackers to run unauthorized code on web servers. This means internet-facing applications could be fully compromised if they use unpatched versions and don't properly validate user input.