CVE-2026-46637

NameCVE-2026-46637
DescriptionTwig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6311-1, DSA-6320-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-twig (PTS)bullseye2.14.3-1+deb11u2vulnerable
bullseye (security)2.14.3-1+deb11u4vulnerable
bookworm, bookworm (security)3.5.1-1+deb12u3fixed
trixie (security), trixie3.27.0-0+deb13u1fixed
forky, sid3.27.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-twigsourcebookworm3.5.1-1+deb12u3DSA-6320-1
php-twigsourcetrixie3.27.0-0+deb13u1DSA-6311-1
php-twigsource(unstable)3.26.0-1

Notes

https://symfony.com/blog/cve-2026-46637-html-output-filters-in-twig-extras-incorrectly-declared-is-safe-all

Search for package or bug name: Reporting problems