Don’t Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) (opens in new tab)
Table of Contents What the sandbox protects againstAbusing the templating engineHow the tab character breaks the Thymeleaf sandboxWhat you need to doThe CVSS score 9.1 is real, but conditional The Thymeleaf vulnerability with a CVSS score of 9.1 grabs your ... The post Don’t Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) appeared first on foojay.
Read the original article