CVE-2026-40478: The Thymeleaf template injection (CVSS 9.1) is conditional. Patch to 3.1.4+ immediately, and audit your code for dynamic view or template expression misuse, which is the key precondition for exploitability.
Don't Panic: The
Exploit
CVE-2026-40478
Snyk Blog
Update to v3.1.4