CVE-2026-46636

NameCVE-2026-46636
DescriptionTwig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6311-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-twig (PTS)bookworm, bookworm (security)3.5.1-1+deb12u3vulnerable
trixie (security), trixie3.27.0-0+deb13u1fixed
forky, sid3.28.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-twigsourcetrixie3.27.0-0+deb13u1DSA-6311-1
php-twigsource(unstable)3.27.0-1

Notes

[bookworm] - php-twig <ignored> (Minor issue, too intrusive to backport)
https://symfony.com/blog/cve-2026-46636-sandbox-filter-tag-and-function-allow-list-bypass-when-sandbox-state-changes-between-renders

Search for package or bug name: Reporting problems