High severity8.1NVD Advisory· Published Jul 14, 2026· Updated Jul 16, 2026
CVE-2026-46638
CVE-2026-46638
Description
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been denied by SecurityPolicy::checkSecurity(). This issue is fixed in version 3.26.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
twig/twigPackagist | < 3.26.0 | 3.26.0 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/twigphp/Twig/commit/819c6a89fe0f261b8555c4f4d5e27d31984223eanvdPatch
- github.com/advisories/GHSA-6j75-5wfj-gh66ghsaADVISORY
- github.com/advisories/GHSA-7fxw-r6jv-74c8ghsaADVISORY
- github.com/twigphp/Twig/security/advisories/GHSA-7fxw-r6jv-74c8nvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46638.yamlghsaWEB
- github.com/twigphp/Twig/releases/tag/v3.26.0nvdRelease Notes
- symfony.com/cve-2026-46638ghsaWEB
News mentions
0No linked articles in our index yet.