{"id":"CVE-2021-43466","aliases":["GHSA-qcj6-jqrg-4wp2"],"url":"https://o3.security/vulnerability/CVE-2021-43466","summary":"Template injection in thymeleaf-spring5","details":"In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.","published":"2021-11-09T12:15:10.693Z","modified":"2026-08-07T19:46:59.498736Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.03993,"percentile":0.89929,"asOf":"2026-09-13"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.thymeleaf:thymeleaf-spring5","fixedVersion":"3.0.13.RELEASE"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20221014-0001/"},{"type":"ADVISORY","url":"https://vuldb.com/?id.186365"},{"type":"EVIDENCE","url":"https://gitee.com/wayne_wwang/wayne_wwang/blob/master/2021/10/31/ruoyi+thymeleaf-rce/index.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T19:46:59.498736Z"}}