DEBIAN-CVE-2026-46637

Source
https://security-tracker.debian.org/tracker/CVE-2026-46637
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46637.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-46637
Upstream
Published
2026-07-14T22:16:56Z
Modified
2026-09-14T17:03:42Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.

References

Affected packages

Debian:12 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.5.1-1+deb12u3

Affected versions

3.*
3.5.1-1
3.5.1-1+deb12u1
3.5.1-1+deb12u2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46637.json"

Debian:13 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.27.0-0+deb13u1

Affected versions

3.*
3.20.0-2
3.21.1-1
3.21.1-2
3.21.1-3
3.22.0-1
3.22.0-2
3.22.1-1
3.22.1-2
3.22.1-3
3.22.2-1
3.22.2-2
3.23.0-1
3.23.0-2
3.24.0-1
3.26.0-0+deb13u1
3.26.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46637.json"

Debian:14 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.0-1

Affected versions

3.*
3.20.0-2
3.21.1-1
3.21.1-2
3.21.1-3
3.22.0-1
3.22.0-2
3.22.1-1
3.22.1-2
3.22.1-3
3.22.2-1
3.22.2-2
3.23.0-1
3.23.0-2
3.24.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46637.json"