← Vulnerability feed

Vulnerability record · CVE-2026-46634 · published 14 July 2026

CVE-2026-46634: Symfony twig vulnerability

Symfony · Twig

Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an inner template without security policy enforcement. This issue is fixed in version 3.26.0.

7.7 CVSS 4.0 High EPSS 0.62% · top 52.6% CWE-693 · CWE-693
7.7CVSS 4.0 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
29 Jul 2026Last modified by NVD

Description

Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an inner template without security policy enforcement. This issue is fixed in version 3.26.0.

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-46634 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-23614Symfony twig injection vulnerabilityTwig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attac…EPSS 8.2%9.8CVE-2018-13818Symfony twig code injection vulnerabilityTwig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is n…EPSS 6.9%8.7CVE-2026-46640Symfony twig code injection vulnerabilityTwig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker…EPSS 0.64%8.7CVE-2026-46633Symfony twig code injection vulnerabilityTwig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is p…EPSS 0.69%8.7CVE-2026-24425Symfony twig vulnerabilityTwig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with te…EPSS 0.76%8.6CVE-2024-45411Symfony twig vulnerabilityTwig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to byp…EPSS 0.85%7.5CVE-2022-39261Symfony twig path traversal vulnerabilityTwig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem…EPSS 3.2%7.5CVE-2001-1537Symfony twig cleartext storage of sensitive data vulnerabilityThe default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which cou…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2026-46634), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.