Medium severity5.4NVD Advisory· Published Jul 14, 2026· Updated Jul 16, 2026
CVE-2026-46628
CVE-2026-46628
Description
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
twig/twigPackagist | < 3.26.0 | 3.26.0 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/twigphp/Twig/commit/3190b9ae12614dfd58cc5d8f394bac4708b17913nvdPatch
- github.com/advisories/GHSA-4j38-f5cw-54h7ghsaADVISORY
- github.com/twigphp/Twig/security/advisories/GHSA-4j38-f5cw-54h7nvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46628.yamlghsaWEB
- github.com/twigphp/Twig/releases/tag/v3.26.0nvdRelease Notes
- symfony.com/cve-2026-46628ghsaWEB
News mentions
0No linked articles in our index yet.