| Bug | bullseye | bookworm | trixie | sid | Description |
|---|
| CVE-2026-47730 | fixed | vulnerable | vulnerable | fixed | |
| CVE-2026-46640 | fixed | fixed | vulnerable | fixed | |
| CVE-2026-46638 | vulnerable | vulnerable | vulnerable | fixed | |
| CVE-2026-46637 | vulnerable | vulnerable | vulnerable | fixed | |
| CVE-2026-46635 | vulnerable | vulnerable | vulnerable | fixed | |
| CVE-2026-46634 | fixed | fixed | vulnerable | fixed | |
| CVE-2026-46633 | vulnerable | vulnerable | vulnerable | fixed | |
| CVE-2026-46629 | vulnerable | vulnerable | vulnerable | fixed | |
| CVE-2026-46628 | vulnerable | vulnerable | vulnerable | fixed | |
| CVE-2026-46627 | vulnerable | vulnerable | vulnerable | fixed | |
| CVE-2026-24425 | vulnerable | vulnerable | vulnerable | fixed | Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass ... |
| CVE-2025-24374 | vulnerable (no DSA, ignored) | vulnerable (no DSA) | fixed | fixed | Twig is a template language for PHP. When using the ?? operator, outpu ... |
| CVE-2024-51755 | vulnerable (no DSA, ignored) | vulnerable (no DSA) | fixed | fixed | Twig is a template language for PHP. In a sandbox, an attacker can acc ... |
| CVE-2024-51754 | fixed | vulnerable (no DSA) | fixed | fixed | Twig is a template language for PHP. In a sandbox, an attacker can cal ... |