| Name | CVE-2026-48807 |
| Description | Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| php-twig (PTS) | bullseye | 2.14.3-1+deb11u2 | fixed |
| bullseye (security) | 2.14.3-1+deb11u4 | fixed |
| bookworm, bookworm (security) | 3.5.1-1+deb12u3 | fixed |
| trixie (security), trixie | 3.27.0-0+deb13u1 | fixed |
| forky, sid | 3.27.1-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| php-twig | source | bullseye | (not affected) | | | |
| php-twig | source | bookworm | (not affected) | | | |
| php-twig | source | trixie | (not affected) | | | |
| php-twig | source | (unstable) | 3.27.0-1 | | | |
Notes
[trixie] - php-twig <not-affected> (Fix for CVE-2026-47732 not yet shipped)
[bookworm] - php-twig <not-affected> (Fix for CVE-2026-47732 not yet shipped)
[bullseye] - php-twig <not-affected> (Fix for CVE-2026-47732 not yet shipped)
https://symfony.com/blog/cve-2026-48807-sandbox-tostring-policy-bypass-via-traversable-in-join-replace-and-in-not-in-operators