CVE-2026-48807

NameCVE-2026-48807
DescriptionTwig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-twig (PTS)bullseye2.14.3-1+deb11u2fixed
bullseye (security)2.14.3-1+deb11u4fixed
bookworm, bookworm (security)3.5.1-1+deb12u3fixed
trixie (security), trixie3.27.0-0+deb13u1fixed
forky, sid3.27.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-twigsourcebullseye(not affected)
php-twigsourcebookworm(not affected)
php-twigsourcetrixie(not affected)
php-twigsource(unstable)3.27.0-1

Notes

[trixie] - php-twig <not-affected> (Fix for CVE-2026-47732 not yet shipped)
[bookworm] - php-twig <not-affected> (Fix for CVE-2026-47732 not yet shipped)
[bullseye] - php-twig <not-affected> (Fix for CVE-2026-47732 not yet shipped)
https://symfony.com/blog/cve-2026-48807-sandbox-tostring-policy-bypass-via-traversable-in-join-replace-and-in-not-in-operators

Search for package or bug name: Reporting problems