CVE-2026-46634 (matched: php)

  • Friday, 31st July, 2026
  • 10:05am

A security issue has been found in Twig, a common template tool used by many PHP-based websites (including widely used content management systems) to build and manage page layouts and content displays.

The flaw impacts Twig versions 3.9.0 up to 3.25.0. In affected versions, the tool’s built-in security sandbox (a feature designed to block untrusted or harmful code from running on your site) can be bypassed when sites use specific Twig functions, allowing unvetted code to run without passing through normal security checks.

This vulnerability is fully resolved in Twig version 3.26.0, which closes the security gap.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-46634

« Back