Security Advisory

CVE-2026-46627

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-14 21:15:17
Last updated 2026-07-16 15:03:37
Assigner GitHub_M
CVSS score 7.1
State PUBLISHED

Description

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.