Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6311-1 | php-twig security update |
Fri, 04 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0. | |
| Title | Twig: Sandbox method allowlist bypass via `Markup` subclass | |
| Weaknesses | CWE-1336 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-04T22:07:35.122Z
Reserved: 2026-05-15T20:11:54.584Z
Link: CVE-2026-46636
No data.
Status : Received
Published: 2026-09-04T22:17:17.360
Modified: 2026-09-04T22:17:17.360
Link: CVE-2026-46636
No data.
OpenCVE Enrichment
Updated: 2026-09-04T23:30:06Z
-
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
Debian DSA