VYPR
Medium severity6.5OSV Advisory· Published Jul 14, 2026· Updated Jul 16, 2026

CVE-2026-46627

CVE-2026-46627

Description

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.

Affected products

2
  • Twigphp/TwigOSV2 versions
    v3.25.0, v3.24.0, v3.23.0, …+ 1 more
    • (no CPE)range: v3.25.0, v3.24.0, v3.23.0, …
    • (no CPE)range: <3.26.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.