Security Advisory

CVE-2026-46627

6.5
MEDIUM

Vulnerability Description

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.
Published Date July 14, 2026
Official Source NIST NVD Advisory