CVE-2026-46633
EUVD-2026-4455814.07.2026, 22:16
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| symfony | twig | 𝑥 < 3.26.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases