Security Advisory

CVE-2026-46629

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-14 21:22:15
Last updated 2026-07-15 12:53:13
Assigner GitHub_M
CVSS score 5.3
State PUBLISHED

Description

Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects that remain pinned for the lifetime of the Twig\Environment. This issue is fixed in version 3.26.0.