Medium severity6.5OSV Advisory· Published Jul 14, 2026· Updated Jul 16, 2026
CVE-2026-46627
CVE-2026-46627
Description
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.