High severity8.2OSV Advisory· Published Jul 14, 2026· Updated Jul 21, 2026
CVE-2026-49981
CVE-2026-49981
Description
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
twig/twigPackagist | < 3.27.0 | 3.27.0 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/twigphp/Twig/commit/23eb6eb1267cb0d303b91eb5cff9b0c559c538a4nvdPatch
- github.com/advisories/GHSA-529h-vh3j-85hqghsaADVISORY
- github.com/twigphp/Twig/security/advisories/GHSA-529h-vh3j-85hqnvdVendor AdvisoryWEB
- github.com/twigphp/Twig/releases/tag/v3.27.0nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.