twig/twig vulnerabilities
CVEs whose affected-version data names the twig/twig package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-49981HighTwig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
▾ Twilighttwig · twig/twigEPSS 0.36%via GHSA
CVE-2026-48805LowTwig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
▾ Sunlittwig · twig/twigEPSS 0.48%via GHSA
CVE-2026-48806MediumTwig: Sandbox `__toString()` policy bypass via dynamic mapping keys
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
▾ Sunlittwig · twig/twigEPSS 0.42%via GHSA
CVE-2026-48807MediumTwig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
▾ Sunlittwig · twig/twigEPSS 0.37%via GHSA
CVE-2026-48808MediumTwig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
▾ Sunlittwig · twig/twigEPSS 0.41%via GHSA