SCA: security update for org.thymeleaf:thymeleaf, org.thymeleaf:thymeleaf-spring5, org.thymeleaf:thymeleaf-spring6 (GHSA-c9ph-gxww-7744)

critical Tenable Cloud Security Plugin ID 441108

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to
3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf.
Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in
some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constructs that
allow this kind of expressions to be executed. If an application developer passes to the template engine
unsanitized variables that contain such expressions, and these values are used in sandboxed contexts
inside the templates, these expressions can be executed achieving Server-Side Template Injection (SSTI).
This vulnerability is fixed in 3.1.5.RELEASE. (CVE-2026-41901)

Solution

Update the org.thymeleaf:thymeleaf library and its related packages to version 3.1.5.RELEASE or later.

See Also

https://github.com/advisories/GHSA-c9ph-gxww-7744

Plugin Details

Severity: Critical

ID: 441108

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 5/5/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.39

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-41901

CVSS v3

Risk Factor: Critical

Base Score: 9

Temporal Score: 7.8

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/4/2026

Vulnerability Publication Date: 5/4/2026

Reference Information

CVE: CVE-2026-41901