INTEL_REPORT
Snyk Blog — AppSec & supply chain · published 4/29/2026, 12:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) CVE-2026-40478: The Thymeleaf template injection (CVSS 9.1) is conditional. Patch to 3.1.4+ immediately, and audit your code for dynamic view or template expression misuse, which is the key precondition for exploitability. The Thymeleaf Template Injection That Only Hurts If You Let It | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk A…
https://snyk.io/blog/thymeleaf-injection
sha256:63dc8eeece136e6852a25b4ea9e04bcb245df536efb47f71e8cdc78f9e199128
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| www.thymeleaf.org |
| Open → |
| domain | templateengine.settemplateresolver | Open → |
| domain | context.setvariable | Open → |
| domain | templateengine.process | Open → |
| domain | resolver.settemplatemode | Open → |
| domain | templatemode.text | Open → |
| domain | org.springframework.core.io.filesystemresource | Open → |
| domain | shell.jsp | Open → |
| url | http://www.thymeleaf.org" | Open → |
| cve | CVE-2026-40478 | Open → |