StackRadar

CVE-2026-40478

Critical

Advisory

Published 15 Apr 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.0
base score, highest
EPSS
0.011
64th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
2 of 2
affected packages

Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
thymeleafmaven3.0.1.RELEASE, 3.0.11.RELEASE3.1.4.RELEASE8
thymeleaf-spring5maven3.0.11.RELEASE3.1.4.RELEASE7
OSV records
GHSA-xjw8-8c5c-9r79

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
spring-petclinic-cloudplatform9-communityVerified publisher0.2.01 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

1 of the 6 container images this version deploys carry CVE-2026-40478.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE

Open the chart page →

41,872
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2026-40478.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE

Open the chart page →

6,711
atlas-cmmsf3k-techVerified publisher0.151.51 of 4See more

atlas-cmms f3k-tech 0.151.5

1 of the 4 container images this version deploys carry CVE-2026-40478.

Container imageDigestPackageFixed in
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE

Open the chart page →

5,291
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-40478.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE

Open the chart page →

8,866
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-40478.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE

Open the chart page →

12,513
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-40478.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE

Open the chart page →

17,702
hapi-fhirhapi-fhirVerified publisher0.1.01 of 1See more

hapi-fhir hapi-fhir 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40478.

Container imageDigestPackageFixed in
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
thymeleaf@3.0.1.RELEASE
3.1.4.RELEASE

Open the chart page →

6,362
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2026-40478.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE

Open the chart page →

12,513
smtp-fake-serversomeblackmagic0.1.01 of 1See more

smtp-fake-server someblackmagic 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40478.

Container imageDigestPackageFixed in
someblackmagic/smtp-fake-server:latest0d63ba37a560
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE

Open the chart page →

4,278
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-40478.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE

Open the chart page →

12,513

Container images carrying it

8 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/shenyu-admin:2.4.2e8b7c4ddd069
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE
3
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE
1
platform9community/admin-server:latestde3fa9b70df1
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
thymeleaf@3.0.1.RELEASE
3.1.4.RELEASE
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
thymeleaf@3.0.11.RELEASE
thymeleaf-spring5@3.0.11.RELEASE
3.1.4.RELEASE
3.1.4.RELEASE
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.