CVE-2026-46627

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.
Configurations

Configuration 1 (hide)

cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-14 22:16

Updated : 2026-07-16 16:19


NVD link : CVE-2026-46627

Mitre link : CVE-2026-46627

CVE.ORG link : CVE-2026-46627


JSON object : View

Products Affected

symfony

  • twig
CWE
CWE-400

Uncontrolled Resource Consumption